Bug ID 1180458
Summary VUL-0: CVE-2020-26215: jupyter, python-jupyter_notebook: open redirect vulnerability
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.1
Hardware Other
URL https://smash.suse.de/issue/272017/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter wolfgang.frisch@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2020-26215

Jupyter Notebook before version 6.1.5 has an Open redirect vulnerability. A
maliciously crafted link to a notebook server could redirect the browser to a
different website. All notebook servers are technically affected, however,
these
maliciously crafted links can only be reasonably made for known notebook server
hosts. A link to your notebook server may appear safe, but ultimately redirect
to a spoofed server on the public internet. The issue is patched in version
6.1.5.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-26215
https://github.com/jupyter/notebook/security/advisories/GHSA-c7vm-f5p4-8fqh
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26215
https://github.com/jupyter/notebook/commit/3cec4bbe21756de9f0c4bccf18cf61d840314d74
https://lists.debian.org/debian-lts-announce/2020/12/msg00004.html


You are receiving this mail because: