{"id":"UBUNTU-CVE-2024-22421","details":"JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version. JupyterLab versions 4.1.0b2, 4.0.11, and 3.6.7 are patched. No workaround has been identified, however users should ensure to upgrade `jupyter-server` to version 2.7.2 or newer which includes a redirect vulnerability fix.","modified":"2026-02-04T03:17:54.692268Z","published":"2024-01-19T21:15:00Z","withdrawn":"2025-06-23T15:57:36Z","related":["CVE-2024-22421"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-22421"},{"type":"REPORT","url":"https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-44cc-43rp-5947"},{"type":"REPORT","url":"https://github.com/jupyterlab/jupyterlab/commit/19bd9b96cb2e77170a67e43121637d0b5619e8c6"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-22421"}],"affected":[{"package":{"name":"jupyter-notebook","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/jupyter-notebook@5.2.2-1ubuntu0.1?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.2.3-4","5.1.0-2","5.2.1-2","5.2.2-1","5.2.2-1ubuntu0.1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-22421.json"}},{"package":{"name":"jupyter-notebook","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/jupyter-notebook@6.0.3-2ubuntu0.1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.7.8-1","6.0.0-1","6.0.0-2","6.0.2-1","6.0.3-1","6.0.3-2","6.0.3-2ubuntu0.1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-22421.json"}},{"package":{"name":"jupyter-notebook","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/jupyter-notebook@6.4.8-1ubuntu0.1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.2.0-1","6.4.5-2","6.4.5-3","6.4.5-4","6.4.8-1","6.4.8-1ubuntu0.1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-22421.json"}},{"package":{"name":"jupyter-notebook","ecosystem":"Ubuntu:24.10","purl":"pkg:deb/ubuntu/jupyter-notebook@6.4.13-2?arch=source&distro=oracular"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.4.12-2.2ubuntu1","6.4.13-2"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-22421.json"}},{"package":{"name":"jupyter-notebook","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/jupyter-notebook@6.4.12-2.2ubuntu1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.4.12-2.2","6.4.12-2.2ubuntu1"],"ecosystem_specific":{"ubuntu_priority":"medium"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-22421.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}