Записи jupyter
68 опубликованных записей вендора jupyter.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 98,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-23 Relative Path Traversal3
- CWE-20 Improper Input Validation3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
68 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2021-39159Эксплойта нет | Remote code execution in Binderhubjupyter · binderhub · CWE-94 | Критическая9,8 | — | 1,9 % | 25 авг. 2021 г. |
40В плане | CVE-2026-44181Эксплойта нет | Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Executionjupyter · enterprise gateway · CWE-1336 | Критическая10,0 | — | 0,8 % | 16 июл. 2026 г. |
40В плане | CVE-2026-44182Эксплойта нет | Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Renderingjupyter · enterprise gateway · CWE-74 | Критическая10,0 | — | 0,6 % | 16 июл. 2026 г. |
39Наблюдать | CVE-2021-32797Эксплойта нет | JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>jupyter · jupyterlab · CWE-79 | Критическая9,6 | — | 2,7 % | 9 авг. 2021 г. |
39Наблюдать | CVE-2021-32798Эксплойта нет | Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in notebookjupyter · notebook · CWE-79 | Критическая9,6 | — | 2,1 % | 9 авг. 2021 г. |
39Наблюдать | CVE-2024-39700Proof of concept | Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Actionjupyter · jupyterlab · CWE-94 | Критическая9,8 | — | 1,1 % | 16 июл. 2024 г. |
39Наблюдать | CVE-2024-28179Эксплойта нет | Jupyter Server Proxy's Websocket Proxying does not require authenticationjupyter · jupyter server proxy · CWE-306 | Критическая9,8 | — | 1,0 % | 20 мар. 2024 г. |
39Наблюдать | CVE-2026-44180Эксплойта нет | Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassedjupyter · enterprise gateway · CWE-20 | Критическая9,8 | — | 0,7 % | 16 июл. 2026 г. |
39Наблюдать | CVE-2024-22415Эксплойта нет | Unsecured endpoints in the jupyter-lsp server extensionjupyter · language server protocol integration · CWE-23 | Критическая9,8 | — | 0,5 % | 18 янв. 2024 г. |
39Наблюдать | CVE-2023-25574Эксплойта нет | JupyterHub's LTI13Authenticator: JWT signature not validatedjupyter · lti jupyterhub authenticator · CWE-347 | Критическая9,8 | — | 0,4 % | 25 февр. 2025 г. |
37Наблюдать | CVE-2026-54527Эксплойта нет | JupyterLab Git: Stored XSS leading to RCEjupyter · jupyterlab-git · CWE-79 | Критическая9,3 | — | 0,5 % | 8 июл. 2026 г. |
37Наблюдать | CVE-2026-44727Эксплойта нет | Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSPjupyter · jupyter server · CWE-79 | Критическая9,3 | — | 0,4 % | 22 июн. 2026 г. |
36Наблюдать | CVE-2018-7206Эксплойта нет | An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3.jupyter · oauthenticator | Высокая8,8 | — | 1,8 % | 17 февр. 2018 г. |
36Наблюдать | CVE-2024-29033Эксплойта нет | GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspacejupyter · oauthenticator · CWE-285 | Критическая9,1 | — | 0,6 % | 20 мар. 2024 г. |
35Наблюдать | CVE-2022-39286Эксплойта нет | Execution with Unnecessary Privileges in JupyterAppjupyter · jupyter core · CWE-250 | Высокая8,8 | — | 1,1 % | 26 окт. 2022 г. |
35Наблюдать | CVE-2022-29241Эксплойта нет | Known or guessable hidden files may be accessed in Jupyter Serverjupyter · jupyter server · CWE-200 | Высокая8,8 | — | 0,9 % | 14 июн. 2022 г. |
35Наблюдать | CVE-2026-42266Эксплойта нет | JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.jupyter · jupyterlab · CWE-88 | Высокая8,8 | — | 0,9 % | 13 мая 2026 г. |
35Наблюдать | CVE-2026-33175Эксплойта нет | OAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email Claimsjupyter · oauthenticator · CWE-287 | Высокая8,8 | — | 0,6 % | 3 апр. 2026 г. |
35Наблюдать | CVE-2026-6657Эксплойта нет | CORS Origin Validation Bypass in jupyter-serverjupyter · jupyter server · CWE-346 | Высокая8,8 | — | 0,3 % | 3 июн. 2026 г. |
34Наблюдать | CVE-2026-42557Эксплойта нет | jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted contentjupyter · jupyterlab · CWE-79 | Высокая8,6 | — | 0,7 % | 13 мая 2026 г. |
34Наблюдать | CVE-2025-53000Эксплойта нет | nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windowsjupyter · nbconvert · CWE-427 | Высокая8,5 | — | 0,3 % | 17 дек. 2025 г. |
32Наблюдать | CVE-2026-5422Эксплойта нет | Path Traversal in jupyter/jupyterjupyter · jupyter server · CWE-23 | Высокая8,1 | — | 0,5 % | 2 июн. 2026 г. |
31Наблюдать | CVE-2018-8768Эксплойта нет | In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context.jupyter · notebook | Высокая7,8 | — | 1,1 % | 18 мар. 2018 г. |
30Наблюдать | CVE-2022-24757Эксплойта нет | Sensitive Auth & Cookie data stored in Jupyter server logsjupyter · jupyter server · CWE-532 | Высокая7,5 | — | 1,3 % | 23 мар. 2022 г. |
30Наблюдать | CVE-2022-24758Эксплойта нет | Insertion of Sensitive Information into Log File affects Jupyter Notebookjupyter · notebook · CWE-532 | Высокая7,5 | — | 1,1 % | 31 мар. 2022 г. |
- CVE-2021-3915940В плане
Remote code execution in Binderhub
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %jupyter · binderhub25 авг. 2021 г.
- CVE-2026-4418140В плане
Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %jupyter · enterprise gateway16 июл. 2026 г.
- CVE-2026-4418240В плане
Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %jupyter · enterprise gateway16 июл. 2026 г.
- CVE-2021-3279739Наблюдать
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
КритическаяCVSS 9,6Эксплойта нетEPSS 3 %jupyter · jupyterlab9 авг. 2021 г.
- CVE-2021-3279839Наблюдать
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in notebook
КритическаяCVSS 9,6Эксплойта нетEPSS 2 %jupyter · notebook9 авг. 2021 г.
- CVE-2024-3970039Наблюдать
Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action
КритическаяCVSS 9,8Proof of conceptEPSS 1 %jupyter · jupyterlab16 июл. 2024 г.
- CVE-2024-2817939Наблюдать
Jupyter Server Proxy's Websocket Proxying does not require authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %jupyter · jupyter server proxy20 мар. 2024 г.
- CVE-2026-4418039Наблюдать
Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %jupyter · enterprise gateway16 июл. 2026 г.
- CVE-2024-2241539Наблюдать
Unsecured endpoints in the jupyter-lsp server extension
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %jupyter · language server protocol integration18 янв. 2024 г.
- CVE-2023-2557439Наблюдать
JupyterHub's LTI13Authenticator: JWT signature not validated
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %jupyter · lti jupyterhub authenticator25 февр. 2025 г.
- CVE-2026-5452737Наблюдать
JupyterLab Git: Stored XSS leading to RCE
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %jupyter · jupyterlab-git8 июл. 2026 г.
- CVE-2026-4472737Наблюдать
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %jupyter · jupyter server22 июн. 2026 г.
- CVE-2018-720636Наблюдать
An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %jupyter · oauthenticator17 февр. 2018 г.
- CVE-2024-2903336Наблюдать
GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %jupyter · oauthenticator20 мар. 2024 г.
- CVE-2022-3928635Наблюдать
Execution with Unnecessary Privileges in JupyterApp
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %jupyter · jupyter core26 окт. 2022 г.
- CVE-2022-2924135Наблюдать
Known or guessable hidden files may be accessed in Jupyter Server
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %jupyter · jupyter server14 июн. 2022 г.
- CVE-2026-4226635Наблюдать
JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %jupyter · jupyterlab13 мая 2026 г.
- CVE-2026-3317535Наблюдать
OAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email Claims
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %jupyter · oauthenticator3 апр. 2026 г.
- CVE-2026-665735Наблюдать
CORS Origin Validation Bypass in jupyter-server
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %jupyter · jupyter server3 июн. 2026 г.
- CVE-2026-4255734Наблюдать
jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %jupyter · jupyterlab13 мая 2026 г.
- CVE-2025-5300034Наблюдать
nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %jupyter · nbconvert17 дек. 2025 г.
- CVE-2026-542232Наблюдать
Path Traversal in jupyter/jupyter
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %jupyter · jupyter server2 июн. 2026 г.
- CVE-2018-876831Наблюдать
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %jupyter · notebook18 мар. 2018 г.
- CVE-2022-2475730Наблюдать
Sensitive Auth & Cookie data stored in Jupyter server logs
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %jupyter · jupyter server23 мар. 2022 г.
- CVE-2022-2475830Наблюдать
Insertion of Sensitive Information into Log File affects Jupyter Notebook
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %jupyter · notebook31 мар. 2022 г.