Alerts This Week
Warning Icon 1 1,153
Alerts This Week
Warning Icon 1 1,153

Fedora 39: FEDORA-2023-3d77cfc654 Critical: Jupyter Server Security Fixes

fedora
Calendar Grey September 15, 2023
Dist Fedora Esm H88
Patch release for Python Jupyter Hub on Fedora addressing vulnerabilities from various issues. Secure your system by using dnf for installation.
Security update with fixes for CVE-2023-39968 and CVE-2023-40170

Summary

The Jupyter Server provides the backend (i.e. the core services,

APIs, and REST endpoints) for Jupyter web applications like

Jupyter notebook, JupyterLab, and Voila.

Update Information:

Security update with fixes for CVE-2023-39968 and CVE-2023-40170

Change Log

* Mon Aug 21 2023 Lumir Balhar - 2.7.2-1 - Update to 2.7.2 (rhbz#2232114)

References


[ 1 ] Bug #2236244 - CVE-2023-40170 python-jupyter-server: improper cross-site credential checks on `/files/` URLs could allow exposure of certain file contents [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2236244 [ 2 ] Bug #2236245 - CVE-2023-39968 python-jupyter-server: Open Redirect Vulnerability [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2236245

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-3d77cfc654' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-jupyter-server
Product: Fedora 39
Version: 2.7.2
Release: 1.fc39
Summary: The backend for Jupyter web applications

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here