« Volver al listado

CVE-2024-28188

Estado: AplazadaMedia (5.3)—

Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-scheduler` users maybe be exposed, potentially revealing information about projects that a specific user may be working on. This vulnerability has been patched in version(s) 1.1.6, 1.2.1, 1.8.2 and 2.5.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-28188",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-28188",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-05-23T15:05:53.639105Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "jupyter-server",
          "product": "jupyter-scheduler",
          "versions": [
            {
              "status": "affected",
              "version": ">= 1.0.0, <= 1.1.5"
            },
            {
              "status": "affected",
              "version": "= 1.2.0"
            },
            {
              "status": "affected",
              "version": ">= 1.3.0, <= 1.8.1"
            },
            {
              "status": "affected",
              "version": ">= 2.0.0, <= 2.5.1"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:jupyter:scheduler:1.0.0:*:*:*:*:*:*:*"
          ],
          "vendor": "jupyter",
          "product": "scheduler",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "versionType": "custom",
              "lessThanOrEqual": "1.1.5"
            },
            {
              "status": "affected",
              "version": "1.2.0"
            },
            {
              "status": "affected",
              "version": "1.3.0",
              "versionType": "custom",
              "lessThanOrEqual": "1.8.1"
            },
            {
              "status": "affected",
              "version": "2.0.0",
              "versionType": "custom",
              "lessThanOrEqual": "2.5.1"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2024-05-23T12:15:10.167",
  "references": [
    {
      "url": "https://github.com/jupyter-server/jupyter-scheduler/security/advisories/GHSA-v9g2-g7j4-4jxc",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jupyter-server/jupyter_server/pull/1392",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/jupyter-server/jupyter-scheduler/security/advisories/GHSA-v9g2-g7j4-4jxc",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/jupyter-server/jupyter_server/pull/1392",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        },
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-scheduler` users maybe be exposed, potentially revealing information about projects that a specific user may be working on. This vulnerability has been patched in version(s) 1.1.6, 1.2.1, 1.8.2 and 2.5.2."
    },
    {
      "lang": "es",
      "value": "Jupyter Scheduler es una colección de extensiones para que los trabajos de programación se ejecuten ahora o según una programación. La lista de entornos conda de los usuarios de \"jupyter-scheduler\" puede quedar expuesta, lo que podría revelar información sobre proyectos en los que un usuario específico puede estar trabajando. Esta vulnerabilidad ha sido parcheada en las versiones 1.1.6, 1.2.1, 1.8.2 y 2.5.2."
    }
  ],
  "lastModified": "2026-06-17T07:21:10.200",
  "sourceIdentifier": "security-advisories@github.com"
}