Open Redirect Vulnerability in Jupyter Notebook by Project Jupyter
CVE-2019-10856

6.1MEDIUM

Key Information:

Vendor

Jupyter

Status
Vendor
CVE Published:
4 April 2019

What is CVE-2019-10856?

An open redirect vulnerability exists in Jupyter Notebook prior to version 5.7.8, which allows attackers to redirect users to arbitrary URLs through the manipulation of the netloc parameter, particularly when it is left empty. This issue is the result of an incomplete remediation for a previous vulnerability and demands immediate attention to mitigate potential risks associated with unauthorized redirections.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.