SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-10856

In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc.

MEDIUM 6.1EPSS 1.26%

Does this matter?

Lower severity and a low EPSS score (1.26%). Track it; it rarely justifies an emergency change on its own.

Description

In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.

CVSS 3.0
6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.26% probability · 68th percentile
CISA KEV
Not listed
Weakness
CWE-601
Affected
jupyter/notebook
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.