Information Exposure Affecting jupyterlab package, versions [,3.6.7) [4.0.0,4.0.11)
Threat Intelligence
EPSS
0.06% (30th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-JUPYTERLAB-6182923
- published 21 Jan 2024
- disclosed 19 Jan 2024
- credit davwwwx
Introduced: 19 Jan 2024
CVE-2024-22421 Open this link in a new tabHow to fix?
Upgrade jupyterlab
to version 3.6.7, 4.0.11 or higher.
Overview
jupyterlab is a JupyterLab computational environment.
Affected versions of this package are vulnerable to Information Exposure due to improper handling of Authorization
and XSRFToken
headers. An attacker can expose sensitive tokens to a third party by convincing a user to click on a malicious link when running an old version of the jupyter-server
component.
Exploiting this vulnerability allows potential authentication and CSRF tokens to leak.
References
CVSS Scores
version 3.1