CVE-2024-28188
jupyter-scheduler's endpoint is missing authentication
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-scheduler` users maybe be exposed, potentially revealing information about projects that a specific user may be working on. This vulnerability has been patched in version(s) 1.1.6, 1.2.1, 1.8.2 and 2.5.2.
Jupyter Scheduler es una colección de extensiones para que los trabajos de programación se ejecuten ahora o según una programación. La lista de entornos conda de los usuarios de "jupyter-scheduler" puede quedar expuesta, lo que podría revelar información sobre proyectos en los que un usuario específico puede estar trabajando. Esta vulnerabilidad ha sido parcheada en las versiones 1.1.6, 1.2.1, 1.8.2 y 2.5.2.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-03-06 CVE Reserved
- 2024-05-23 CVE Published
- 2024-05-24 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/jupyter-server/jupyter-scheduler/security/advisories/GHSA-v9g2-g7j4-4jxc | X_refsource_confirm | |
https://github.com/jupyter-server/jupyter_server/pull/1392 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jupyter-server Search vendor "Jupyter-server" | Jupyter-scheduler Search vendor "Jupyter-server" for product "Jupyter-scheduler" | >= 1.0.0 <= 1.1.5 Search vendor "Jupyter-server" for product "Jupyter-scheduler" and version " >= 1.0.0 <= 1.1.5" | en |
Affected
| ||||||
Jupyter-server Search vendor "Jupyter-server" | Jupyter-scheduler Search vendor "Jupyter-server" for product "Jupyter-scheduler" | 1.2.0 Search vendor "Jupyter-server" for product "Jupyter-scheduler" and version "1.2.0" | en |
Affected
| ||||||
Jupyter-server Search vendor "Jupyter-server" | Jupyter-scheduler Search vendor "Jupyter-server" for product "Jupyter-scheduler" | >= 1.3.0 <= 1.8.1 Search vendor "Jupyter-server" for product "Jupyter-scheduler" and version " >= 1.3.0 <= 1.8.1" | en |
Affected
| ||||||
Jupyter-server Search vendor "Jupyter-server" | Jupyter-scheduler Search vendor "Jupyter-server" for product "Jupyter-scheduler" | >= 2.0.0 <= 2.5.1 Search vendor "Jupyter-server" for product "Jupyter-scheduler" and version " >= 2.0.0 <= 2.5.1" | en |
Affected
|