QID 996185

Date Published: 2023-12-13

QID 996185: Python (Pip) Security Update for jupyter-server (GHSA-h56g-gq9v-vc8r)

Unhandled errors in API requests include traceback information, which can include path information. There is no known mechanism by which to trigger these errors without authentication, so the paths revealed are not considered particularly sensitive, given that the requesting user has arbitrary execution permissions already in the same environment.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-h56g-gq9v-vc8r for updates and patch information.
    Vendor References

    CVEs related to QID 996185

    Software Advisories
    Advisory ID Software Component Link
    GHSA-h56g-gq9v-vc8r jupyter-server URL Logo github.com/advisories/GHSA-h56g-gq9v-vc8r