[Bug 1218976] New: VUL-0: CVE-2024-22415: jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of jupyter-lsp running in environments without confi ...
https://bugzilla.suse.com/show_bug.cgi?id=1218976 Bug ID: 1218976 Summary: VUL-0: CVE-2024-22415: jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of jupyter-lsp running in environments without confi ... Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.6 Hardware: Other URL: https://smash.suse.de/issue/391707/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: code@bnavigator.de Reporter: smash_bz@suse.de QA Contact: security-team@suse.de CC: stoyan.manolov@suse.com Target Milestone: --- Found By: Security Response Team Blocker: --- jupyter-lsp is a coding assistance tool for JupyterLab (code navigation + hover suggestions + linters + autocompletion + rename) using Language Server Protocol. Installations of jupyter-lsp running in environments without configured file system access control (on the operating system level), and with jupyter-server instances exposed to non-trusted network are vulnerable to unauthorised access and modification of file system beyond the jupyter root directory. This issue has been patched in version 2.2.2 and all users are advised to upgrade. Users unable to upgrade should uninstall jupyter-lsp. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-22415 https://github.com/jupyter-lsp/jupyterlab-lsp/security/advisories/GHSA-4qhp-... https://www.cve.org/CVERecord?id=CVE-2024-22415 https://github.com/jupyter-lsp/jupyterlab-lsp/commit/4ad12f204ad0b85580fc321... -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1218976 Maintenance Automation <maint-coord+maintenance-robot@suse.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Priority|P5 - None |P3 - Medium -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1218976 https://bugzilla.suse.com/show_bug.cgi?id=1218976#c2 Benjamin Greiner <code@bnavigator.de> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|code@bnavigator.de |security-team@suse.de Status|NEW |CONFIRMED --- Comment #2 from Benjamin Greiner <code@bnavigator.de> --- Fixed for Factory, reassigning back for the SUSE SLE15 maintainer, if there is one -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com