CVE-2019-10255

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jupyter:jupyterhub:*:*:*:*:*:*:*:*
cpe:2.3:a:jupyter:notebook:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:02

Type Values Removed Values Added
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VMDPJBVXOVO6LYGAT46VZNHH6JKSCURO/', 'name': 'FEDORA-2019-9e67979b2a', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UP5RLEES2JBBNSNLBR65XM6PCD4EMF7D/', 'name': 'FEDORA-2019-a6e1287e76', 'tags': [], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMDPJBVXOVO6LYGAT46VZNHH6JKSCURO/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UP5RLEES2JBBNSNLBR65XM6PCD4EMF7D/ -
References (MISC) https://github.com/jupyter/notebook/compare/05aa4b2...16cf97c - Patch, Third Party Advisory (MISC) https://github.com/jupyter/notebook/compare/05aa4b2...16cf97c - Third Party Advisory, Patch

Information

Published : 2019-03-28 16:29

Updated : 2023-12-10 12:59


NVD link : CVE-2019-10255

Mitre link : CVE-2019-10255

CVE.ORG link : CVE-2019-10255


JSON object : View

Products Affected

jupyter

  • jupyterhub
  • notebook
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')