GHSA-m87f-39q9-6f55
HIGHCVE-2022-24758Anytime a 5xx error is triggered, the auth cookie and other header values are recorded in Jupyter server logs by default. Considering these logs do not require root access, an attacker can monitor these logs, steal sensitive auth/cookie information, and gain access to the Jupyter server.
- Affected
- >=0, <6.4.10
- Fixed in
- 6.4.10
- Published
- 2022-04-05
- Source
- github