QID 983218

QID 983218: Python (pip) Security Update for notebook (GHSA-c7vm-f5p4-8fqh)

[localhost](http://localhost:8888)

_What kind of vulnerability is it? Who is impacted?_

Open redirect vulnerability - a maliciously crafted link to a notebook server could redirect the browser to a different website.

All notebook servers are technically affected, however, these maliciously crafted links can only be reasonably made for known notebook server hosts. A link to your notebook server may *appear* safe, but ultimately redirect to a spoofed server on the public internet.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    _Has the problem been patched? What versions should users upgrade to?_

    Patched in notebook 6.1.5
    Vendor References

    CVEs related to QID 983218

    Software Advisories
    Advisory ID Software Component Link
    GHSA-c7vm-f5p4-8fqh notebook URL Logo github.com/advisories/GHSA-c7vm-f5p4-8fqh