Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-22420


JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicious Markdown file using JupyterLab preview feature. A malicious user can access any data that the attacked user has access to as well as perform arbitrary requests acting as the attacked user. JupyterLab version 4.0.11 has been patched. Users are advised to upgrade. Users unable to upgrade should disable the table of contents extension.


Published

2024-01-19T21:15:09.667

Last Modified

2024-11-21T08:56:15.203

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jupyter jupyterlab < 4.0.11 Yes
Application jupyter notebook < 7.0.7 Yes
Operating System fedoraproject fedora 39 Yes

References