CVE-2019-10255

Description

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.462

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Vulnerabilities CVE-2019-10255,CVE-2019-10856 are fixed in Python-notebook 5.7.8Windows
Vulnerabilities CVE-2019-10255 are fixed in Python-jupyterhub 0.9.6Windows
Jupyter interactive notebook (USN-5585-1) python-notebook_5.2.2-1ubuntu0.1_all.debLinux
Jupyter interactive notebook (USN-5585-1) jupyter-notebook_5.2.2-1ubuntu0.1_all.debLinux
Jupyter interactive notebook (USN-5585-1) jupyter-notebook_6.0.3-2ubuntu0.1_all.debLinux
Jupyter interactive notebook (USN-5585-1) jupyter-notebook_6.4.8-1ubuntu0.1_all.debLinux
Jupyter interactive notebook (USN-5585-1) python3-notebook_5.2.2-1ubuntu0.1_all.debLinux
Jupyter interactive notebook (USN-5585-1) python3-notebook_6.0.3-2ubuntu0.1_all.debLinux
Jupyter interactive notebook (USN-5585-1) python3-notebook_6.4.8-1ubuntu0.1_all.debLinux
Vulnerabilities CVE-2019-10255,CVE-2019-10856 are fixed in Python-notebook for linux 5.7.8Linux
Vulnerabilities CVE-2019-10255 are fixed in Python-jupyterhub for linux 0.9.6Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234