jupyter-server is vulnerable to Insertion of Sensitive Information into Log File
71
High Risk
When Jupyter Server returns a 500 error it serializes the incoming request headers to the server log as JSON. The Referer header is copied, so when a client authenticates with a token embedded in the request URL that token is carried in the Referer and written to the logs in clear text. Anyone able to read the server logs can then recover valid authentication tokens and reuse them to impersonate the user. The fix scrubs sensitive query parameters from the Referer value before logging, replacing secret values with a placeholder.
You are affected if you are using a version that falls within the vulnerable range.
jupyter-server is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.1 - 2.20.0.
Upgrade the jupyter-server and/or the jupyter_server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.