Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.845500
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-5585-1)
Summary:The remote host is missing an update for the 'jupyter-notebook' package(s) announced via the USN-5585-1 advisory.
Description:Summary:
The remote host is missing an update for the 'jupyter-notebook' package(s) announced via the USN-5585-1 advisory.

Vulnerability Insight:
It was discovered that Jupyter Notebook incorrectly handled certain notebooks.
An attacker could possibly use this issue of lack of Content Security Policy
in Nbconvert to perform cross-site scripting (XSS) attacks on the notebook
server. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-19351)

It was discovered that Jupyter Notebook incorrectly handled certain SVG
documents. An attacker could possibly use this issue to perform cross-site
scripting (XSS) attacks. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-21030)

It was discovered that Jupyter Notebook incorrectly filtered certain URLs on
the login page. An attacker could possibly use this issue to perform
open-redirect attack. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-10255)

It was discovered that Jupyter Notebook had an incomplete fix for
CVE-2019-10255. An attacker could possibly use this issue to perform
open-redirect attack using empty netloc. (CVE-2019-10856)

It was discovered that Jupyter Notebook incorrectly handled the inclusion of
remote pages on Jupyter server. An attacker could possibly use this issue to
perform cross-site script inclusion (XSSI) attacks. This issue only affected
Ubuntu 18.04 LTS. (CVE-2019-9644)

It was discovered that Jupyter Notebook incorrectly filtered certain URLs to a
notebook. An attacker could possibly use this issue to perform open-redirect
attack. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.
(CVE-2020-26215)

It was discovered that Jupyter Notebook server access logs were not protected.
An attacker having access to the notebook server could possibly use this issue
to get access to steal sensitive information such as auth/cookies.
(CVE-2022-24758)

It was discovered that Jupyter Notebook incorrectly configured hidden files on
the server. An authenticated attacker could possibly use this issue to see
unwanted sensitive hidden files from the server which may result in getting
full access to the server. This issue only affected Ubuntu 20.04 LTS and
Ubuntu 22.04 LTS. (CVE-2022-29238)

Affected Software/OS:
'jupyter-notebook' package(s) on Ubuntu 18.04, Ubuntu 20.04, Ubuntu 22.04.

Solution:
Please install the updated package(s).

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-19351
https://github.com/jupyter/notebook/blob/master/docs/source/changelog.rst
https://github.com/jupyter/notebook/commit/107a89fce5f413fb5728c1c5d2c7788e1fb17491
https://groups.google.com/forum/#!topic/jupyter/hWzu2BSsplY
https://pypi.org/project/notebook/#history
https://lists.debian.org/debian-lts-announce/2020/11/msg00033.html
Common Vulnerability Exposure (CVE) ID: CVE-2018-21030
https://github.com/jupyter/notebook/pull/3341
https://github.com/jupyter/notebook/releases/tag/5.5.0
Common Vulnerability Exposure (CVE) ID: CVE-2019-10255
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VMDPJBVXOVO6LYGAT46VZNHH6JKSCURO/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UP5RLEES2JBBNSNLBR65XM6PCD4EMF7D/
https://blog.jupyter.org/open-redirect-vulnerability-in-jupyter-jupyterhub-adf43583f1e4
https://github.com/jupyter/notebook/commit/08c4c898182edbe97aadef1815cce50448f975cb
https://github.com/jupyter/notebook/commit/70fe9f0ddb3023162ece21fbb77d5564306b913b
https://github.com/jupyter/notebook/commit/d65328d4841892b412aef9015165db1eb029a8ed
https://github.com/jupyter/notebook/compare/05aa4b2...16cf97c
Common Vulnerability Exposure (CVE) ID: CVE-2019-10856
https://github.com/jupyter/notebook/compare/16cf97c...b8e30ea
Common Vulnerability Exposure (CVE) ID: CVE-2019-9644
https://github.com/jupyter/notebook/compare/f3f00df...05aa4b2
Common Vulnerability Exposure (CVE) ID: CVE-2020-26215
https://github.com/jupyter/notebook/security/advisories/GHSA-c7vm-f5p4-8fqh
https://github.com/jupyter/notebook/commit/3cec4bbe21756de9f0c4bccf18cf61d840314d74
https://lists.debian.org/debian-lts-announce/2020/12/msg00004.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-24758
https://github.com/jupyter/notebook/security/advisories/GHSA-m87f-39q9-6f55
Common Vulnerability Exposure (CVE) ID: CVE-2022-29238
https://github.com/jupyter/notebook/security/advisories/GHSA-v7vq-3x77-87vg
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.