CVE-2025-32428
Severity CVSS v4.0:
CRITICAL
Type:
Unavailable / Other
Publication date:
15/04/2025
Last modified:
15/04/2025
Description
Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the network. This vulnerability does not affect users having TurboVNC as the vncserver executable. This issue is fixed in 3.0.1.
Impact
Base Score 4.0
9.00
Severity 4.0
CRITICAL