QID 996755

Date Published: 2024-01-23

QID 996755: Python (Pip) Security Update for jupyter-lsp (GHSA-4qhp-652w-c22x)

Installations of jupyter-lsp running in environments without configured file system access control (on the operating system level), and with jupyter-server instances exposed to non-trusted network are vulnerable to unauthorised access and modification of file system beyond the jupyter root directory. Please note this vulnerability is in the extension and is patched in version 2.2.2 of that extension. This extension has been updated in jupyterlab-lsp version 5.0.2.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-4qhp-652w-c22x for updates and patch information.
    Vendor References

    CVEs related to QID 996755

    Software Advisories
    Advisory ID Software Component Link
    GHSA-4qhp-652w-c22x jupyter-lsp URL Logo github.com/advisories/GHSA-4qhp-652w-c22x