jupyter-server is vulnerable to Origin Validation Error
61
Medium Risk
jupyter-server validates allow_origin_pat with prefix-style regular expression matching. A malicious origin that begins with a trusted domain can pass checks intended for only that trusted origin. The bypass affects CORS headers, WebSocket origin checks, referer validation, and login redirects when this configuration is used. The fix switches origin validation to full-string matching and adds tests for bypass origins.
You are affected if you are using a version that falls within the vulnerable range.
jupyter-server is vulnerable to Origin Validation Error in versions 1.12.0 - 2.17.0.
Upgrade the jupyter-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant