Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 832051 (CVE-2022-21697) - <dev-python/jupyter-server-proxy-3.2.1: authenticated server side request forgery
Summary: <dev-python/jupyter-server-proxy-3.2.1: authenticated server side request for...
Status: RESOLVED FIXED
Alias: CVE-2022-21697
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa]
Keywords:
: 832052 (view as bug list)
Depends on:
Blocks:
 
Reported: 2022-01-25 15:51 UTC by John Helmert III
Modified: 2022-03-24 16:41 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-01-25 15:51:58 UTC
CVE-2022-21697 (https://github.com/jupyterhub/jupyter-server-proxy/security/advisories/GHSA-gcv9-6737-pjqw):

Jupyter Server Proxy is a Jupyter notebook server extension to proxy web services. Versions of Jupyter Server Proxy prior to 3.2.1 are vulnerable to Server-Side Request Forgery (SSRF). Any user deploying Jupyter Server or Notebook with jupyter-proxy-server extension enabled is affected. A lack of input validation allows authenticated clients to proxy requests to other hosts, bypassing the `allowed_hosts` check. Because authentication is required, which already grants permissions to make the same requests via kernel or terminal execution, this is considered low to moderate severity. Users may upgrade to version 3.2.1 to receive a patch or, as a workaround, install the patch manually.

Please bump to 3.2.1.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-01-25 16:02:45 UTC
Sorry, just needs cleanup.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-01-25 16:03:05 UTC
*** Bug 832052 has been marked as a duplicate of this bug. ***
Comment 3 Andrew Ammerlaan gentoo-dev 2022-03-24 09:00:30 UTC
I cleaned this one while I was cleaning up the rest of jupyter and friends (Bug 835869)
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-24 16:41:28 UTC
All done!