CVE-2022-29241 is a high-severity vulnerability affecting Jupyter Server versions prior to 1.17.1. It allows an authenticated attacker to leak the server's access token by guessing the PID if the server's root_dir includes the user's home directory. This flaw, with a CVSS score of 8.8, enables an attacker to interact with Jupyter services, potentially modifying critical files like .bashrc or .ssh/authorized_keys, leading to sensitive data exposure and system compromise. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.0CPE matchmatch criteria | cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.