CVE-2019-10255

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
28/03/2019
Last modified:
07/11/2023

Description

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jupyter:jupyterhub:*:*:*:*:*:*:*:* 0.9.5 (excluding)
cpe:2.3:a:jupyter:notebook:*:*:*:*:*:*:*:* 5.7.7 (excluding)