CVE-2024-28188

EUVD-2024-1797
Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-scheduler` users maybe be exposed, potentially revealing information about projects that a specific user may be working on. This vulnerability has been patched in version(s) 1.1.6, 1.2.1, 1.8.2 and 2.5.2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
jupyterscheduler
1.0.0 ≤
𝑥
≤ 1.1.5
ADP
jupyterscheduler
1.3.0 ≤
𝑥
≤ 1.8.1
ADP
jupyterscheduler
2.0.0 ≤
𝑥
≤ 2.5.1
ADP
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jupyter-server
focal
dne
jammy
needs-triage
mantic
ignored
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage