Min RK
33 exploits
Active since Sep 2015
JupyterHub: Cross-origin form POSTs bypass XSRF
CVSS 5.4
IPython 3.x < 3.2 - Cross-Site Scripting via JSON Error Messages
CVSS 6.1
IPython < 3.2.0 - Cross-Site Scripting via JSON Error Messages
CVSS 6.1
IPython 2-3 - Cross-Site Request Forgery in REST API
CVSS 8.8
JupyterHub < 0.9.5 and Jupyter Notebook < 5.7.7 - Open Redirect via Login Page
CVSS 6.1
JupyterHub < 0.9.5 and Jupyter Notebook < 5.7.7 - Open Redirect via Login Page
CVSS 6.1
JupyterHub <4.1.6, 5.1.0 - Privilege Escalation
CVSS 7.2
OAuthenticator: Authentication Bypass in Auth0OAuthenticator via Unverified Email Claims
CVSS 8.8
IPython 2-3 - Cross-Site Request Forgery in REST API
CVSS 8.8
IPython Notebook < 3.2.2 and Jupyter Notebook 4.0.0-4.0.4 - Remote Code Execution via Crafted File MIME Type
IPython Notebook < 3.2.2 and Jupyter Notebook 4.0.0-4.0.4 - Remote Code Execution via Crafted File MIME Type
Jupyter Notebook < 5.7.2 - Cross-Site Scripting via Crafted Directory Name
CVSS 6.1
JupyterHub < 0.9.5 and Jupyter Notebook < 5.7.7 - Open Redirect via Login Page
CVSS 6.1
jupyterhub-kubespawner <0.12 - Privilege Escalation
CVSS 6.8
Jupyter Notebook < 6.1.5 - Open Redirect via Maliciously Crafted Link
CVSS 4.4
OAuthenticator <0.12.2 - Info Disclosure
CVSS 6.3
jupyterhub-systemdspawner < 0.15 - Unauthenticated User API Token Exposure via Systemd Environment
CVSS 7.9
Jupyter Server <1.1.1 - Open Redirect
CVSS 6.1
nbgitpuller 0.9.0-0.10.1 - OS Command Injection via Malicious Link
CVSS 9.6
JupyterHub 1.0.0-1.5.0 - Insufficient Session Expiration via Multiple JupyterLab Tabs
CVSS 3.5
jupyter_server_proxy < 3.2.1 - Authenticated Server-Side Request Forgery via Allowed Hosts Bypass
CVSS 6.3
jupyter_server < 2.7.2 - Open Redirect via Malicious Login Links
CVSS 4.3
jupyter_server < 2.7.2 - Improper Access Control in Files Endpoint
CVSS 4.6
dockerspawner 0.11.0-12.x - Unauthenticated Arbitrary Docker Image Execution via Missing allowed_images Configuration
CVSS 8.0
jupyter_server < 2.11.2 - Authenticated Sensitive Information Exposure via API Error Traceback
CVSS 3.5