Junglewise Threat Intelligence

CVE-2020-26232: PYSEC-2020-234 - Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server could redirect the br

CVE-2020-26232 · Severity: low · CVSS 3.1 · Published 2020-11-24

Technologies: jupyter-server (PyPI). Vendors: PyPI.

Executive brief

Jupyter Server before version 1.0.6 has an Open redirect vulnerability. A maliciously crafted link to a jupyter server could redirect the browser to a different website. All jupyter servers are technically affected, however, these maliciously crafted links can only be reasonably made for known jupyter server hosts. A link to your jupyter server may appear safe, but ultimately redirect to a spoofed server on the public internet.

Affected products

  • PyPI jupyter-server

Related threats