Перейти к содержимому
Noroxi

Записи jupyter

68 опубликованных записей вендора jupyter.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
9
С записью об исправлении
98,5 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

68 записей
  • CVE-2021-39159
    40В плане

    Remote code execution in Binderhub

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    jupyter · binderhub25 авг. 2021 г.

  • CVE-2026-44181
    40В плане

    Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    jupyter · enterprise gateway16 июл. 2026 г.

  • CVE-2026-44182
    40В плане

    Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    jupyter · enterprise gateway16 июл. 2026 г.

  • CVE-2021-32797
    39Наблюдать

    JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>

    КритическаяCVSS 9,6Эксплойта нетEPSS 3 %

    jupyter · jupyterlab9 авг. 2021 г.

  • CVE-2021-32798
    39Наблюдать

    Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in notebook

    КритическаяCVSS 9,6Эксплойта нетEPSS 2 %

    jupyter · notebook9 авг. 2021 г.

  • CVE-2024-39700
    39Наблюдать

    Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub Action

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    jupyter · jupyterlab16 июл. 2024 г.

  • CVE-2024-28179
    39Наблюдать

    Jupyter Server Proxy's Websocket Proxying does not require authentication

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    jupyter · jupyter server proxy20 мар. 2024 г.

  • CVE-2026-44180
    39Наблюдать

    Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    jupyter · enterprise gateway16 июл. 2026 г.

  • CVE-2024-22415
    39Наблюдать

    Unsecured endpoints in the jupyter-lsp server extension

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    jupyter · language server protocol integration18 янв. 2024 г.

  • CVE-2023-25574
    39Наблюдать

    JupyterHub's LTI13Authenticator: JWT signature not validated

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    jupyter · lti jupyterhub authenticator25 февр. 2025 г.

  • CVE-2026-54527
    37Наблюдать

    JupyterLab Git: Stored XSS leading to RCE

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    jupyter · jupyterlab-git8 июл. 2026 г.

  • CVE-2026-44727
    37Наблюдать

    Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    jupyter · jupyter server22 июн. 2026 г.

  • CVE-2018-7206
    36Наблюдать

    An issue was discovered in Project Jupyter JupyterHub OAuthenticator 0.6.x before 0.6.2 and 0.7.x before 0.7.3.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    jupyter · oauthenticator17 февр. 2018 г.

  • CVE-2024-29033
    36Наблюдать

    GoogleOAuthenticator.hosted_domain incorrectly verifies membership of an Google organization/workspace

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    jupyter · oauthenticator20 мар. 2024 г.

  • CVE-2022-39286
    35Наблюдать

    Execution with Unnecessary Privileges in JupyterApp

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    jupyter · jupyter core26 окт. 2022 г.

  • CVE-2022-29241
    35Наблюдать

    Known or guessable hidden files may be accessed in Jupyter Server

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    jupyter · jupyter server14 июн. 2022 г.

  • CVE-2026-42266
    35Наблюдать

    JupyterLab has an Extension Manager API/GUI Policy Discrepancy allowing 3rd party (malicious) extensions install via POST request.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    jupyter · jupyterlab13 мая 2026 г.

  • CVE-2026-33175
    35Наблюдать

    OAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email Claims

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    jupyter · oauthenticator3 апр. 2026 г.

  • CVE-2026-6657
    35Наблюдать

    CORS Origin Validation Bypass in jupyter-server

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    jupyter · jupyter server3 июн. 2026 г.

  • CVE-2026-42557
    34Наблюдать

    jupyterlab: Command linker attributes in HTML enable one-click command execution from untrusted content

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    jupyter · jupyterlab13 мая 2026 г.

  • CVE-2025-53000
    34Наблюдать

    nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    jupyter · nbconvert17 дек. 2025 г.

  • CVE-2026-5422
    32Наблюдать

    Path Traversal in jupyter/jupyter

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    jupyter · jupyter server2 июн. 2026 г.

  • CVE-2018-8768
    31Наблюдать

    In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    jupyter · notebook18 мар. 2018 г.

  • CVE-2022-24757
    30Наблюдать

    Sensitive Auth & Cookie data stored in Jupyter server logs

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    jupyter · jupyter server23 мар. 2022 г.

  • CVE-2022-24758
    30Наблюдать

    Insertion of Sensitive Information into Log File affects Jupyter Notebook

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    jupyter · notebook31 мар. 2022 г.