QID 376124

Date Published: 2021-12-02

QID 376124: Jupyter Notebook Open Redirect Vulnerability

Jupyter Notebook is an open-source web application that allows you to create and share documents that contain live code, equations, visualizations and narrative text. Uses include data cleaning and transformation, numerical simulation, statistical modeling, data visualization, machine learning, and much more.

Affected versions
Prior to 6.1.5
QID Detection Logic:(authenticated)
This QID checks for Jupyter Notebook version by using the command line.

A maliciously crafted link to a notebook server could redirect the browser to a different website.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Please refer to this security advisory JUPYTER to address this issue and obtain further details.

    CVEs related to QID 376124

    Software Advisories
    Advisory ID Software Component Link
    GHSA-c7vm-f5p4-8fqh URL Logo github.com/jupyter/notebook/security/advisories/GHSA-c7vm-f5p4-8fqh