Bug 1214731 (CVE-2023-40170) - VUL-0: CVE-2023-40170: python-jupyter-server: jupyter-server is the backend for Jupyter web applications. Improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents, or accessing files when opening
Summary: VUL-0: CVE-2023-40170: python-jupyter-server: jupyter-server is the backend f...
Status: RESOLVED FIXED
Alias: CVE-2023-40170
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/376565/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-40170:4.6:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-29 07:29 UTC by Cathy Hu
Modified: 2024-05-29 12:17 UTC (History)
5 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Cathy Hu 2023-08-29 07:29:35 UTC
CVE-2023-40170

jupyter-server is the backend for Jupyter web applications. Improper cross-site
credential checks on `/files/` URLs could allow exposure of certain file
contents, or accessing files when opening untrusted files via  "Open image in
new tab". This issue has been addressed in commit `87a49272728` which has been
included in release `2.7.2`. Users are advised to upgrade. Users unable to
upgrade may use the lower performance
`--ContentsManager.files_handler_class=jupyter_server.files.handlers.FilesHandler`,
which implements the correct checks.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-40170
https://www.cve.org/CVERecord?id=CVE-2023-40170
https://github.com/jupyter-server/jupyter_server/commit/87a4927272819f0b1cae1afa4c8c86ee2da002fd
https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-64x5-55rw-9974
Comment 1 Cathy Hu 2023-08-29 07:29:48 UTC
Affected:
- SUSE:ALP:Source:Standard:1.0/python-jupyter-server  2.5.0
- openSUSE:Factory/python-jupyter-server              2.6.0
Comment 2 OBSbugzilla Bot 2023-08-29 08:05:04 UTC
This is an autogenerated message for OBS integration:
This bug (1214731) was mentioned in
https://build.opensuse.org/request/show/1107864 Factory / python-jupyter-server
Comment 3 Markéta Machová 2023-08-29 12:53:31 UTC
https://build.suse.de/request/show/306404, I hope it is the correct workflow
Comment 5 Robert Frohl 2024-05-29 12:17:49 UTC
done, closing