RULE(RULE ID:338778)

Rule General Information
Release Date: 2025-04-02
Rule Name: Jupyter Server jupyter-scheduler Unauthorized Access Vulnerability (CVE-2024-28188)
Severity:
CVE ID:
Rule Protection Details
Description: Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-scheduler` users maybe be exposed, potentially revealing information about projects that a specific user may be working on. This vulnerability has been patched in version(s) 1.1.6, 1.2.1, 1.8.2 and 2.5.2.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://github.com/jupyter-server/jupyter-scheduler/security/advisories/GHSA-v9g2-g7j4-4jxc
https://github.com/jupyter-server/jupyter_server/pull/1392
Solutions
Please refer to announcements or patches release by the vendor: https://github.com/jupyter-server/jupyter-scheduler/security/advisories/GHSA-v9g2-g7j4-4jxc