4.6.2
10 years ago
20 days ago
Known vulnerabilities in the jupyterlab package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
jupyterlab is a JupyterLab computational environment. Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output in the import of a crafted Note: This is only exploitable if the attacker can write to a directory from which the application loads settings, or if the user imports a malicious settings file. How to fix Improper Encoding or Escaping of Output? Upgrade | [3.3.0,4.5.10)[4.6.0a0,4.6.2) |
jupyterlab is a JupyterLab computational environment. Affected versions of this package are vulnerable to Incorrect Behavior Order: Validate Before Canonicalize when enforcing blocklists for extension installation due to insufficient normalization of package names. An attacker can bypass intended package restrictions by submitting alternative spellings that resolve to blocked packages, allowing installation of unauthorized extensions and potentially impacting the integrity and availability of the server by exhausting resources. Note: This is only exploitable if a custom allowlist or blocklist is configured, the PyPI Extension Manager is enabled, and kernels and terminals are disabled or delegated to remote hosts. How to fix Incorrect Behavior Order: Validate Before Canonicalize? Upgrade | [,4.5.10)[4.6.0a0,4.6.2) |
jupyterlab is a JupyterLab computational environment. Affected versions of this package are vulnerable to Not Failing Securely ('Failing Open') in the Note: This is only exploitable if a custom extension or downstream integration calls How to fix Not Failing Securely ('Failing Open')? Upgrade | [,4.5.10)[4.6.0a0,4.6.2) |
jupyterlab is a JupyterLab computational environment. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? Upgrade | [,4.5.10)[4.6.0a0,4.6.2) |
jupyterlab is a JupyterLab computational environment. Affected versions of this package are vulnerable to Incorrect Authorization in the enforcement of plugin manager lock rules via direct API requests to How to fix Incorrect Authorization? Upgrade | [,4.5.10)[4.6.0a0,4.6.2) |