Vulnerability index

Browse CVEs

55 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Language Server Protocol Integration CRITICAL 9.8
CVE-2024-22415

jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Serve…

Fix: 2.2.2+
Fix from $2,300 2024-01-18
Jupyter Server MEDIUM 6.1
CVE-2023-39968

jupyter-server is the backend for Jupyter web applications. Open Redirect Vulnerability. Maliciously crafted login links to known Jupyter Servers can…

Fix: 2.7.2+
Fix from $1,600 2023-08-28
Jupyter Server MEDIUM 6.1
CVE-2023-40170

jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain f…

Fix: 2.7.2+
Fix from $1,600 2023-08-28
Nbconvert MEDIUM 5.4
CVE-2021-32862

The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTM…

Fix: after 6.2.0
Fix from $1,600 2022-08-18
Jupyter Server HIGH 8.8
CVE-2022-29241

Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter Notebook. Prior to v…

Fix: 1.17.0+
Fix from $1,950 2022-06-14
Oauthenticator MEDIUM 6.5
CVE-2022-31027

OAuthenticator is an OAuth token library for the JupyerHub login handler. CILogonOAuthenticator is provided by the OAuthenticator package, and lets u…

Fix: 15.0.0+
Fix from $1,600 2022-06-09
Notebook HIGH 7.5
CVE-2022-24758

The Jupyter notebook is a web-based notebook environment for interactive computing. Prior to version 6.4.9, unauthorized actors can access sensitive …

Fix: 6.4.10+
Fix from $1,950 2022-03-31
Jupyter Server HIGH 7.5
CVE-2022-24757

The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications. Prior to version 1.15.4, una…

Fix: 1.15.4+
Fix from $1,950 2022-03-23
Jupyter Server Proxy HIGH 7.1
CVE-2022-21697

Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to 3.2.1 are vulnerable to …

Fix: 3.2.1+
Fix from $1,950 2022-01-25
Jupyterhub HIGH 7.5
CVE-2021-41247

JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple JupyterLab tabs open in the same b…

Fix: 1.5.0+
Fix from $1,950 2021-11-04
Nbdime MEDIUM 5.4
CVE-2021-41134

nbdime provides tools for diffing and merging of Jupyter Notebooks. In affected versions a stored cross-site scripting (XSS) issue exists within the …

Fix: 1.0.1 / 1.1.1+
Fix from $1,600 2021-11-03
Binderhub CRITICAL 9.8
CVE-2021-39159

BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments from code repositories. In a…

Fix: 0.2.0-n653+
Fix from $2,300 2021-08-25
Jupyterlab CRITICAL 9.6
CVE-2021-32797

JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted noteboo…

Fix: 1.2.21 / 2.2.10+
Fix from $2,300 2021-08-09
Notebook CRITICAL 9.6
CVE-2021-32798

The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load.…

Fix: 5.7.11+
Fix from $2,300 2021-08-09
Jupyter Server MEDIUM 6.1
CVE-2020-26275

The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, Jupyte…

Fix: 1.1.1+
Fix from $1,600 2020-12-21
Oauthenticator MEDIUM 6.3
CVE-2020-26250

OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2…

Fix: 0.12.2+
Fix from $1,600 2020-12-01
Jupyter Server MEDIUM 5.4
CVE-2020-26232

Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server could redirect the browser to …

Fix: 1.0.6+
Fix from $1,600 2020-11-24
Notebook MEDIUM 5.3
CVE-2018-21030

Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload ca…

Fix: 5.5.0+
Fix from $1,600 2019-10-31
Notebook MEDIUM 6.1
CVE-2019-10856

In Jupyter Notebook before 5.7.8, an open redirect can occur via an empty netloc. This issue exists because of an incomplete fix for CVE-2019-10255.

Fix: 5.7.8+
Fix from $1,600 2019-04-04
Jupyterhub MEDIUM 6.1
CVE-2019-10255

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allow…

Fix: 0.9.5 / 5.7.7+
Fix from $1,600 2019-03-28
Notebook MEDIUM 5.4
CVE-2019-9644

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users …

Fix: 5.7.6+
Fix from $1,600 2019-03-12
Notebook MEDIUM 6.1
CVE-2018-19351

Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook…

Fix: 5.7.1+
Fix from $1,600 2018-11-18
Notebook MEDIUM 6.1
CVE-2018-19352

Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.

Fix: 5.7.2+
Fix from $1,600 2018-11-18
Notebook HIGH 7.8
CVE-2018-8768

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifica…

Fix: 5.4.1+
Fix from $1,950 2018-03-18
Oauthenticator HIGH 8.8
CVE-2018-7206

An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3. When using JupyterHub with GitLab gro…

Patch available
Fix from $1,950 2018-02-18