CVE-2024-35178

The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attackers leak the NTLMv2 password hash of the Windows user running the Jupyter server. An attacker can crack this password to gain access to the Windows machine hosting the Jupyter server, or access other network-accessible machines or 3rd party services using that credential. Or an attacker perform an NTLM relay attack without cracking the credential to gain access to other network-accessible machines. This vulnerability is fixed in 2.14.1.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

24 Oct 2024, 19:22

Type Values Removed Values Added
References () https://github.com/jupyter-server/jupyter_server/commit/79fbf801c5908f4d1d9bc90004b74cfaaeeed2df - () https://github.com/jupyter-server/jupyter_server/commit/79fbf801c5908f4d1d9bc90004b74cfaaeeed2df - Patch
References () https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-hrw6-wg82-cm62 - () https://github.com/jupyter-server/jupyter_server/security/advisories/GHSA-hrw6-wg82-cm62 - Vendor Advisory
CWE NVD-CWE-noinfo
First Time Jupyter
Jupyter jupyter Server
Microsoft
Microsoft windows
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:jupyter:jupyter_server:*:*:*:*:*:*:*:*

07 Jun 2024, 14:56

Type Values Removed Values Added
Summary
  • (es) Jupyter Server proporciona el backend para las aplicaciones web de Jupyter. Jupyter Server en Windows tiene una vulnerabilidad que permite a atacantes no autenticados filtrar el hash de contraseña NTLMv2 del usuario de Windows que ejecuta el servidor Jupyter. Un atacante puede descifrar esta contraseña para obtener acceso a la máquina Windows que aloja el servidor Jupyter, o acceder a otras máquinas accesibles en red o servicios de terceros utilizando esa credencial. O un atacante realiza un ataque de retransmisión NTLM sin descifrar la credencial para obtener acceso a otras máquinas accesibles en la red. Esta vulnerabilidad se solucionó en 2.14.1.

06 Jun 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-06 16:15

Updated : 2024-10-24 19:22


NVD link : CVE-2024-35178

Mitre link : CVE-2024-35178

CVE.ORG link : CVE-2024-35178


JSON object : View

Products Affected

microsoft

  • windows

jupyter

  • jupyter_server
CWE
NVD-CWE-noinfo CWE-200

Exposure of Sensitive Information to an Unauthorized Actor