jupyter Vulnerabilities and Affected Products
Vulnerabilities associated with extension-template.
Products
Clear product- notebook6 vulnerabilities
- nbconvert4 vulnerabilities
- jupyter/jupyter3 vulnerabilities
- jupyter_core2 vulnerabilities
- jupyter_server2 vulnerabilities
- extension-template1 vulnerability
- jupyter_server_proxy1 vulnerability
- nbdime1 vulnerability
- nbgrader1 vulnerability
- scheduler1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-39700CRITICAL | Remote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub ActionJupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to `update-integration-tests.yml`, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions… CWE-94Jul 16, 2024 | CVSS10.0v3.1 | EPSS1.02% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |