Vulnerability Details CVE-2024-22421
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version. JupyterLab versions 4.1.0b2, 4.0.11, and 3.6.7 are patched. No workaround has been identified, however users should ensure to upgrade `jupyter-server` to version 2.7.2 or newer which includes a redirect vulnerability fix.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.4%
CVSS Severity
CVSS v3 Score 7.6
Products affected by CVE-2024-22421
-
cpe:2.3:a:jupyter:jupyterlab:-
-
cpe:2.3:a:jupyter:jupyterlab:4.0.0
-
cpe:2.3:a:jupyter:notebook:7.0.0
-
cpe:2.3:o:fedoraproject:fedora:39