Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 832051 (CVE-2022-21697)

Summary: <dev-python/jupyter-server-proxy-3.2.1: authenticated server side request forgery
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: trivial CC: andrewammerlaan, filip.ambroz, sci
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
See Also: https://bugs.gentoo.org/show_bug.cgi?id=835869
Whiteboard: ~4 [noglsa]
Package list:
Runtime testing required: ---

Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-01-25 15:51:58 UTC
CVE-2022-21697 (https://github.com/jupyterhub/jupyter-server-proxy/security/advisories/GHSA-gcv9-6737-pjqw):

Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to 3.2.1 are vulnerable to Server-Side Request Forgery (SSRF). Any user deploying Jupyter Server or Notebook with jupyter-proxy-server extension enabled is affected. A lack of input validation allows authenticated clients to proxy requests to other hosts, bypassing the `allowed_hosts` check. Because authentication is required, which already grants permissions to make the same requests via kernel or terminal execution, this is considered low to moderate severity. Users may upgrade to version 3.2.1 to receive a patch or, as a workaround, install the patch manually.

Please bump to 3.2.1.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-01-25 16:02:45 UTC
Sorry, just needs cleanup.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-01-25 16:03:05 UTC
*** Bug 832052 has been marked as a duplicate of this bug. ***
Comment 3 Andrew Ammerlaan gentoo-dev 2022-03-24 09:00:30 UTC
I cleaned this one while I was cleaning up the rest of jupyter and friends (Bug 835869)
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-24 16:41:28 UTC
All done!