Jupyterhub Jupyterhub

Do you want an email whenever new security vulnerabilities are reported in Jupyterhub?

By the Year

In 2024 there have been 0 vulnerabilities in Jupyterhub . Jupyterhub did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 1 7.50
2020 0 0.00
2019 1 6.10
2018 0 0.00

It may take a day or so for new Jupyterhub vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Jupyterhub Security Vulnerabilities

JupyterHub is an open source multi-user server for Jupyter notebooks

CVE-2021-41247 7.5 - High - November 04, 2021

JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple JupyterLab tabs open in the same browser session, may see incomplete logout from the single-user server, as fresh credentials (for the single-user server only, not the Hub) reinstated after logout, if another active JupyterLab session is open while the logout takes place. Upgrade to JupyterHub 1.5. For distributed deployments, it is jupyterhub in the _user_ environment that needs patching. There are no patches necessary in the Hub environment. The only workaround is to make sure that only one JupyterLab tab is open when you log out.

Insufficient Session Expiration

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5

CVE-2019-10255 6.1 - Medium - March 28, 2019

An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.

Open Redirect

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Canonical Ubuntu Linux or by Jupyter? Click the Watch button to subscribe.

Jupyter
Vendor

Jupyterhub
Product

subscribe