VDB
EN
MEDIUM 6.1

GHSA-3vff-hjqv-m7h8

JupyterHub has an Open Redirect Vulnerability

상세

## Affected Version

JupyterHub <= 5.4.3

## Impact

An open redirect vulnerability in JupyterHub <=5.4.3 allows attackers to construct links which, when clicked, take users to the JupyterHub login page, after which they are sent to an arbitrary attacker-controlled site outside JupyterHub instead of a JupyterHub page, bypassing JupyterHub's check to prevent this.

## Patches

Upgrade to JupyterHub 5.4.4

## Workarounds

A deployment can apply filters on the Location header in a reverse proxy such as nginx/apache/traefik.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / jupyterhub
최초 영향 버전: 0 수정 버전: 5.4.4
수정 pip install --upgrade 'jupyterhub>=5.4.4'

참고