{"id":"UBUNTU-CVE-2022-29241","details":"Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter Notebook. Prior to version 1.17.1, if notebook server is started with a value of `root_dir` that contains the starting user's home directory, then the underlying REST API can be used to leak the access token assigned at start time by guessing/brute forcing the PID of the jupyter server. While this requires an authenticated user session, this URL can be used from a cross-site scripting payload or from a hooked or otherwise compromised browser to leak this access token to a malicious third party. This token can be used along with the REST API to interact with Jupyter services/notebooks such as modifying or overwriting critical files, such as .bashrc or .ssh/authorized_keys, allowing a malicious user to read potentially sensitive data and possibly gain control of the impacted system. This issue is patched in version 1.17.1.","modified":"2026-05-20T16:06:42.966112587Z","published":"2022-06-14T21:15:00Z","upstream":["CVE-2022-29241"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-29241"},{"type":"REPORT","url":"https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-q874-g24w-4q9g"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-29241"}],"affected":[{"package":{"name":"jupyter-server","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/jupyter-server?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.2.2-1","1.13.1-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.13.1-1","binary_name":"jupyter-server"},{"binary_version":"1.13.1-1","binary_name":"python3-jupyter-server"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-29241.json"}},{"package":{"name":"jupyter-server","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/jupyter-server?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.23.3-1","1.23.3-2"],"ecosystem_specific":{"binaries":[{"binary_name":"jupyter-server","binary_version":"1.23.3-2"},{"binary_name":"python3-jupyter-server","binary_version":"1.23.3-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-29241.json"}},{"package":{"name":"jupyter-server","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/jupyter-server?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.14.2-5","2.15.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"jupyter-server","binary_version":"2.15.0-1"},{"binary_version":"2.15.0-1","binary_name":"python3-jupyter-server"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-29241.json"}},{"package":{"name":"jupyter-server","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/jupyter-server?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.15.0-1","2.17.0-1"],"ecosystem_specific":{"binaries":[{"binary_name":"jupyter-server","binary_version":"2.17.0-1"},{"binary_name":"python3-jupyter-server","binary_version":"2.17.0-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-29241.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}