Jupyter Security Sprint March 31st
This is a critical moment for open source software. AI enables new contributors in new ways, but maintainers are also faced with an unprecedented...
This is a critical moment for open source software. AI enables new contributors in new ways, but maintainers are also faced with an unprecedented...
Three Jupyter Subprojects – Jupyter Server, JupyterLab, and JupyterHub –are participating in a bug bounty program sponsored by the European...
This requirement and the outlined plan was discussed and agreed upon at the Jupyter Governance meeting on Friday, July 1, 2022.
We are aware of ransomware attacks specifically targeting Jupyter servers.
Trusted CI is the US National Science Foundation Cybersecurity Center of Excellence, staffed by cybersecurity experts who have spent decades...
On August 26 it was revealed that a misconfiguration in Microsoft’s internal deployment of CosmosDB using Jupyter would allow attackers to access...
TL:DR; All recent JupyterLab and Notebook versions are susceptible to a attack where a maliciously crafted notebook can trigger arbitrary code...
Update: notebook 5.7.7 and JupyterHub 0.9.5 contained incomplete fixes for this issue. 5.7.8 and 0.9.6 are released with more complete fixes.
We have just released Jupyter notebook 5.7.6 with a security fix for a cross-site inclusion (XSSI) vulnerability, where content from a Jupyter...
Two security issues have been found and fixed this week, where untrusted javascript could be executed if malicious files could be delivered to the...
We have just released Jupyter Notebook 5.6.0. This release fixes a vulnerability that could allow a maliciously crafted notebook to execute...
This vulnerability has been assigned CVE-2018-7206
tl;dr: don’t disable notebook authentication!
We have just released Jupyter Notebook 4.3.0 and 4.3.1 with some important security fixes.
A version of ipywidget has been released, which fixes important security issues.
TL;DR: upgrade to notebook 4.2.2