Total vulnerabilities in the database
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their Authorization
and XSRFToken
tokens exposed to a third party when running an older jupyter-server
version. JupyterLab versions 4.1.0b2, 4.0.11, and 3.6.7 are patched. No workaround has been identified, however users should ensure to upgrade jupyter-server
to version 2.7.2 or newer which includes a redirect vulnerability fix.
Software | From | Fixed in |
---|---|---|
![]() |
4.0.0 | 4.0.11 |
![]() |
- | 3.6.7 |
![]() |
7.0.0 | 7.0.7 |
jupyter / notebook | 7.0.0 | 7.0.7 |
jupyter / jupyterlab | 4.0.0 | 4.0.11 |
jupyter / jupyterlab | - | 3.6.7 |
fedoraproject / fedora | 39 | 39.x |