SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-22421

Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version.

MEDIUM 6.5EPSS 0.67%

Does this matter?

Lower severity and a low EPSS score (0.67%). Track it; it rarely justifies an emergency change on its own.

Description

JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version. JupyterLab versions 4.1.0b2, 4.0.11, and 3.6.7 are patched. No workaround has been identified, however users should ensure to upgrade `jupyter-server` to version 2.7.2 or newer which includes a redirect vulnerability fix.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
0.67% probability · 50th percentile
CISA KEV
Not listed
Weakness
CWE-23, CWE-200
Affected
jupyter/jupyterlab · jupyter/notebook · fedoraproject/fedora
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.