Loading
An Open Redirect vulnerability for all browsers in Jupyter Notebook before 5.7.7 and some browsers (Chrome, Firefox) in JupyterHub before 0.9.5 allows crafted links to the login page, which will redirect to a malicious site after successful login. Servers running on a base_url prefix are not affected.
Use CWE-601, Jupyter vendor hub and Jupyterhub product page to widen CVE-2019-10255 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-28233, CVE-2024-41942 and CVE-2026-33709 for nearby disclosures in the same product family.