CVE-2019-10255
Summary
| CVE | CVE-2019-10255 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-28 16:29:00 UTC |
| Updated | 2023-11-07 03:02:00 UTC |
| Description | An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| protect against chrome mishandling backslash as slash in URLs · jupyter/notebook@08c4c89 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 30 Update: python-notebook-5.7.8-1.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| changelog for redirect check · jupyter/notebook@d65328d · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 30 Update: python-notebook-5.7.8-1.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 29 Update: python-notebook-5.7.8-1.fc29 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Comparing 05aa4b2...16cf97c · jupyter/notebook · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Open Redirect Vulnerability in Jupyter, JupyterHub – Jupyter Blog |
MISC |
blog.jupyter.org |
Vendor Advisory |
| parse urls when validating redirect targets · jupyter/notebook@70fe9f0 · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| [SECURITY] Fedora 29 Update: python-notebook-5.7.8-1.fc29 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 198916 Ubuntu Security Notification for Jupyter Notebook Vulnerabilities (USN-5585-1)
- 980870 Python (pip) Security Update for jupyterhub (GHSA-rv62-4pmj-xw6h)