CVE-2024-28233
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-28233 is a newly disclosed vulnerability affecting JupyterHub, an open-source multi-user platform for Jupyter notebooks. Malicious actors can exploit this Cross-Site Scripting (XSS) issue by luring users to visit a malicious subdomain, allowing the attacker to inject malicious code into the user's session. In a JupyterHub context, this XSS attack grants the attacker access to the JupyterHub API and control over the user's single-user server. This vulnerability poses a threat to single-origin JupyterHub deployments and installations with user-controlled applications running on subdomains or peer subdomains. The vulnerability has been addressed in JupyterHub version 4.1.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.