icon

We found results for “

CVE-2024-28188

Good to know:

icon

Date: May 23, 2024

Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of "jupyter-scheduler" users maybe be exposed, potentially revealing information about projects that a specific user may be working on. This vulnerability has been patched in version(s) 1.1.6, 1.2.1, 1.8.2 and 2.5.2.

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Improper Authentication

CWE-287

Exposure of Sensitive Information to an Unauthorized Actor

CWE-200

Top Fix

icon

Upgrade Version

Upgrade to version jupyter-scheduler - 1.8.2;jupyter-scheduler - 2.5.2;jupyter-scheduler - 1.1.6;jupyter-scheduler - 1.2.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us