3.3.0
8 years ago
29 days ago
Known vulnerabilities in the jupyter-enterprise-gateway package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
jupyter-enterprise-gateway is an A web server for spawning and communicating with remote Jupyter kernels Affected versions of this package are vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') via the rendering process of Kubernetes manifests using untrusted environment variables in Jinja2 templates. An attacker can inject arbitrary YAML content, overwrite critical fields such as How to fix Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')? Upgrade | [,3.3.0) |
jupyter-enterprise-gateway is an A web server for spawning and communicating with remote Jupyter kernels Affected versions of this package are vulnerable to Improper Neutralization of Special Elements Used in a Template Engine via the rendering of Kubernetes manifest templates using untrusted environment variables in the How to fix Improper Neutralization of Special Elements Used in a Template Engine? Upgrade | [2.0.0rc2,3.3.0) |
jupyter-enterprise-gateway is an A web server for spawning and communicating with remote Jupyter kernels Affected versions of this package are vulnerable to Incorrect Behavior Order: Validate Before Canonicalize via improper validation of the How to fix Incorrect Behavior Order: Validate Before Canonicalize? Upgrade | [2.0.0rc1,3.3.0) |