Vulnerability Description
The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. In Jupyter Server before version 1.1.1, an open redirect vulnerability could cause the jupyter server to redirect the browser to a different malicious website. All jupyter servers running without a base_url prefix are technically affected, however, these maliciously crafted links can only be reasonably made for known jupyter server hosts. A link to your jupyter server may *appear* safe, but ultimately redirect to a spoofed server on the public internet. This same vulnerability was patched in upstream notebook v5.7.8. This is fixed in jupyter_server 1.1.1. If upgrade is not available, a workaround can be to run your server on a url prefix: "jupyter server --ServerApp.base_url=/jupyter/".
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jupyter | Jupyter Server | < 1.1.1 |
Related Weaknesses (CWE)
References
- https://advisory.checkmarx.net/advisory/CX-2020-4291ExploitThird Party Advisory
- https://github.com/jupyter-server/jupyter_server/commit/85e4abccf6ea9321d29153f7PatchThird Party Advisory
- https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-9f66-5PatchThird Party Advisory
- https://pypi.org/project/jupyter-server/Product
- https://advisory.checkmarx.net/advisory/CX-2020-4291ExploitThird Party Advisory
- https://github.com/jupyter-server/jupyter_server/commit/85e4abccf6ea9321d29153f7PatchThird Party Advisory
- https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-9f66-5PatchThird Party Advisory
- https://pypi.org/project/jupyter-server/Product
FAQ
What is CVE-2020-26275?
CVE-2020-26275 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter notebook, JupyterLab, and Voila. In Jupyter Server before version 1...
How severe is CVE-2020-26275?
CVE-2020-26275 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26275?
Check the references section above for vendor advisories and patch information. Affected products include: Jupyter Jupyter Server.