QID 980888

QID 980888: Python (pip) Security Update for notebook (GHSA-rcx2-m7jp-p9wj)

In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Customers are advised to refer to GHSA-rcx2-m7jp-p9wj for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980888

    Software Advisories
    Advisory ID Software Component Link
    GHSA-rcx2-m7jp-p9wj notebook URL Logo github.com/advisories/GHSA-rcx2-m7jp-p9wj