jupyter-server@2.11.1 vulnerabilities

The backend—i.e. core services, APIs, and REST endpoints—to Jupyter web applications.

Direct Vulnerabilities

Known vulnerabilities in the jupyter-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Generation of Error Message Containing Sensitive Information

Affected versions of this package are vulnerable to Generation of Error Message Containing Sensitive Information. When handling API requests from an authenticated user, unhandled errors include traceback information, which can reveal path information. The revealed paths are not considered particularly sensitive, given that the requesting user has arbitrary execution permissions already in the same environment.

How to fix Generation of Error Message Containing Sensitive Information?

Upgrade jupyter-server to version 2.11.2 or higher.

[,2.11.2)