<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Jupyter Blog - security</title><link href="https://jasongrout.github.io/medium-archive/pelican/" rel="alternate"/><link href="https://jasongrout.github.io/medium-archive/pelican/feeds/tag-security.atom.xml" rel="self"/><id>https://jasongrout.github.io/medium-archive/pelican/</id><updated>2026-03-20T19:47:00+00:00</updated><subtitle>The Project Jupyter blog: news, releases, and community stories, archived from blog.jupyter.org.</subtitle><entry><title>Jupyter Security Sprint March 31st</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2026/jupyter-security-sprint-march-31st/" rel="alternate"/><published>2026-03-20T19:47:00+00:00</published><updated>2026-03-20T19:47:00+00:00</updated><author><name>Joe Lucas </name></author><id>tag:jasongrout.github.io,2026-03-20:/medium-archive/pelican/posts/2026/jupyter-security-sprint-march-31st/</id><summary type="html">&lt;p&gt;This is a critical moment for open source software. AI enables new contributors in new ways, but maintainers are also faced with an…&lt;/p&gt;
</summary><content type="html">&lt;p&gt;&lt;img src="https://jasongrout.github.io/medium-archive/pelican/posts/2026/jupyter-security-sprint-march-31st/images/001-1_OphBxiSYkkxD-KWM4wcatA.webp" alt="" loading="lazy" data-body-image=""&gt;&lt;/p&gt;
&lt;p&gt;This is a critical moment for open source software. AI enables new contributors in new ways, but maintainers are also faced with an unprecedented volume of contributions and security reports. This speed also puts pressure on maintainers and the processes that keep projects secure and reliable.&lt;/p&gt;
&lt;p&gt;At the same time, there have been significant recent advances in tooling for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;dependency analysis&lt;/li&gt;
&lt;li&gt;vulnerability scanning&lt;/li&gt;
&lt;li&gt;supply chain security&lt;/li&gt;
&lt;li&gt;automated security checks in CI pipelines&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;But many open source software projects still struggle to evaluate and integrate these tools into their workflows.&lt;/p&gt;
&lt;h2 id="the-security-tooling-sprint"&gt;The Security Tooling Sprint&lt;/h2&gt;
&lt;p&gt;To help address this challenge, the Linux Foundation and the Berkeley Institute for Data Science (BIDS) are hosting the &lt;a href="https://events.linuxfoundation.org/security-tooling-sprint/"&gt;Security Tooling Sprint&lt;/a&gt; on March 31st. This sprint will bring together maintainers, security experts, and contributors to explore how security tooling can better support the secure development of &lt;a href="https://jupyter.org/"&gt;Project Jupyter&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Participants will work to understand what tools exist, what problems they solve, and how they can be used in real projects.&lt;/p&gt;
&lt;h2 id="what-we-will-do"&gt;What We Will Do&lt;/h2&gt;
&lt;p&gt;During the sprint, participants will work together to explore the current landscape of security tooling and apply it to real workflows.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://events.linuxfoundation.org/security-tooling-sprint/program/schedule/"&gt;Activities will include&lt;/a&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;identifying common maintainer pain points&lt;/li&gt;
&lt;li&gt;reviewing the modern security tooling ecosystem&lt;/li&gt;
&lt;li&gt;experimenting with tools in real project environments&lt;/li&gt;
&lt;li&gt;sharing results and ideas with the group&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The event focuses on collaboration and hands-on exploration in order to derive actionable recommendations back as issues and pull requests.&lt;/p&gt;
&lt;h2 id="why-this-matters-for-jupyter"&gt;Why This Matters for Jupyter&lt;/h2&gt;
&lt;p&gt;Project Jupyter is used by millions of people in research, education, and industry. Like many open source projects, it relies on a global community of maintainers and contributors volunteering their time, energy, and expertise.&lt;/p&gt;
&lt;p&gt;Improving security practices helps protect users while reducing maintainer burden and strengthening trust in the ecosystem.&lt;/p&gt;
&lt;h2 id="join-us"&gt;Join Us&lt;/h2&gt;
&lt;p&gt;If you are interested in open source security, developer tooling, or the future of the Jupyter ecosystem, we encourage you to participate.&lt;/p&gt;
&lt;p&gt;Learn more and &lt;a href="https://events.linuxfoundation.org/security-tooling-sprint/"&gt;register here&lt;/a&gt;. We hope you will join us in Berkeley and help improve how to evolve how open source communities approach security.&lt;/p&gt;
</content><category term="security"/></entry><entry><title>European Commission Funds Jupyter Bug Bounty Program</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2023/european-commission-funds-jupyter-bug-bounty-program/" rel="alternate"/><published>2023-07-28T19:46:00+00:00</published><updated>2023-07-28T19:46:00+00:00</updated><author><name>Rick Wagner</name></author><id>tag:jasongrout.github.io,2023-07-28:/medium-archive/pelican/posts/2023/european-commission-funds-jupyter-bug-bounty-program/</id><summary type="html">&lt;p&gt;Three Jupyter Subprojects – Jupyter Server, JupyterLab, and JupyterHub –are participating in a bug bounty program sponsored by the European…&lt;/p&gt;
</summary><content type="html">&lt;p&gt;Three Jupyter Subprojects – Jupyter Server, JupyterLab, and JupyterHub –are participating in a &lt;a href="https://app.intigriti.com/programs/jupyter/jupyter/detail"&gt;bug bounty program&lt;/a&gt; &lt;a href="https://commission.europa.eu/news/european-commissions-open-source-programme-office-starts-bug-bounties-2022-01-19_en"&gt;sponsored by the European Commission&lt;/a&gt; and hosted on the &lt;a href="https://www.intigriti.com/"&gt;Intigriti platform&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://jasongrout.github.io/medium-archive/pelican/posts/2023/european-commission-funds-jupyter-bug-bounty-program/images/001-1_8C-9fnjUJwJ56vdcNX0-bA.webp" alt="Screenshot showing the bug bounty program description on the Intigriti site." loading="lazy" data-body-image=""&gt;&lt;/p&gt;
&lt;p&gt;Intigriti is a cybersecurity company that specializes in crowdsourced security services like &lt;a href="https://www.intigriti.com/landing/bug-bounty"&gt;bug bounty programs&lt;/a&gt;, hybrid penetration testing, and hosting live hacking events. The financial support covers bounties from €250 to €5,000 and is part of the European Commission’s &lt;a href="https://commission.europa.eu/about-european-commission/departments-and-executive-agencies/informatics/open-source-software-strategy_en"&gt;Open Source Software Strategy 2020–2023&lt;/a&gt;, which:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Promotes the sharing and reuse of software solutions, knowledge and expertise, to deliver better European services that benefit society and lower costs to that society. The Commission commits to increasing its use of open source not only in practical areas such as IT, but also in areas where it can be strategic.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This is a great opportunity for Project Jupyter to reduce the number of potential vulnerabilities in critical Jupyter components and to evaluate our vulnerability handling processes.&lt;/p&gt;
&lt;p&gt;Project Jupyter was selected for sponsorship at the end of 2022. After discussions involving several Jupyter Subprojects and other stakeholders, the three Jupyter software components were chosen for inclusion. Representatives from Jupyter Server, JupyterLab, and JupyterHub have committed to validating and responding to submissions for their area. Focusing on a limited number of key Jupyter components was a way to balance the benefits of identifying vulnerabilities against developer obligations to review vulnerability submissions. The Jupyter Security Subproject is contributing to this effort by drafting the bug bounty program details and being a liaison between Intigriti and the other Jupyter Subprojects.&lt;/p&gt;
&lt;p&gt;Submissions are triaged by Intigriti, including reproducing potential vulnerabilities and assigning a severity. The triage process ensures that submissions fall within the scope (software components, versions, etc.) defined by the program. Vulnerability severity is based on Intigriti’s &lt;a href="https://kb.intigriti.com/en/articles/5041991-intigriti-s-contextual-cvss-standard"&gt;contextualized Common Vulnerability Scoring System (CVSS)&lt;/a&gt; and assigned a rating of low, medium, high, critical, or exceptional. The severity determines both the bounty and the response time for Project Jupyter to validate a submission. After a submission passes triage, it is sent to Project Jupyter for validation.&lt;/p&gt;
&lt;p&gt;Project Jupyter appreciates the financial support from the European Commission and the help by Intigriti representatives to establish the program. Security researchers and others interested in the bug bounty program can view the details &lt;a href="https://app.intigriti.com/programs/jupyter/jupyter/detail"&gt;on the Intigriti website&lt;/a&gt;.&lt;/p&gt;
</content><category term="funding"/><category term="security"/></entry><entry><title>Requiring 2FA for Jupyter GitHub Organizations</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2022/requiring-2fa-for-jupyter-github-organizations/" rel="alternate"/><published>2022-07-05T15:00:00+00:00</published><updated>2022-08-11T09:23:00+00:00</updated><author><name>Rick Wagner</name></author><id>tag:jasongrout.github.io,2022-07-05:/medium-archive/pelican/posts/2022/requiring-2fa-for-jupyter-github-organizations/</id><summary type="html">&lt;p&gt;This requirement and the outlined plan was discussed and agreed upon at the Jupyter Governance meeting on Friday, July 1, 2022.&lt;/p&gt;
</summary><content type="html">&lt;p&gt;&lt;em&gt;This requirement and the outlined plan was discussed and agreed upon at the Jupyter Governance meeting on Friday, July 1, 2022.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;By October 1, 2022, Project Jupyter aims to &lt;a href="https://docs.github.com/en/organizations/keeping-your-organization-secure/managing-two-factor-authentication-for-your-organization/requiring-two-factor-authentication-in-your-organization"&gt;require two-factor authentication (2FA)&lt;/a&gt; for all GitHub organizations hosting repositories for &lt;a href="https://jupyter.org/governance/list_of_subprojects.html#official-subprojects-with-ssc-representation"&gt;official Jupyter Subprojects&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.blog/2021-08-16-securing-your-github-account-two-factor-authentication/"&gt;Enabling 2FA&lt;/a&gt; is the single most important step Jupyter contributors can take to protect their GitHub accounts from bad actors. This benefits the entire Jupyter Community by reducing the chance for malicious code to be slipped into a repository.&lt;/p&gt;
&lt;p&gt;Fortunately, most Jupyter GitHub organization members and external collaborators have 2FA enabled, at this time. This process will get us to 100% so we can enable the requirement as a GitHub org setting.&lt;/p&gt;
&lt;h2 id="whats-the-process"&gt;What’s the process?&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://docs.github.com/en/authentication/securing-your-account-with-two-factor-authentication-2fa"&gt;GitHub Documentation on 2FA&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;We recommend that all GitHub users secure their account with 2FA, even if you don’t have an organizational role like admin or owner, or write permissions to a Jupyter repository.&lt;/p&gt;
&lt;p&gt;Over the next month (by August 1, 2022) contributors to the Jupyter Security Subproject will reach out to owners of each Jupyter GitHub org with a list of their users without 2FA enabled. The list of users will be an intersection across the GitHub orgs so that users aren’t contacted multiple times, and org maintainers are asked to do double work.&lt;/p&gt;
&lt;p&gt;From there, the org owners can decide how they want to work within their area of the Community. They may choose to contact the users or ask the Security Subproject to reach out to the users. Or, the users without 2FA may no longer need the access or role they were granted.&lt;/p&gt;
&lt;p&gt;At end of August, 2022, we’ll review the list of the remaining accounts without 2FA. (Hopefully none!) If possible, we’ll begin enabling the requirement on our GitHub orgs. The Security Subproject will work with org owners on plans for contacting any remaining users.&lt;/p&gt;
&lt;p&gt;At the end of September, 2022, users without 2FA enabled may lose explicit permissions or roles within Jupyter GitHub orgs. This will only impact access to private repositories, commit privileges, or having a role such as owner or admin. Read access to public repositories will remain the same, along with opening issues or pull requests. And once users enable 2FA on their account, any previous permissions or roles can be restored.&lt;/p&gt;
&lt;h2 id="what-github-orgs-does-this-apply-to"&gt;What GitHub orgs does this apply to?&lt;/h2&gt;
&lt;p&gt;All GitHub orgs hosting repositories for &lt;a href="https://jupyter.org/governance/list_of_subprojects.html#official-subprojects-with-ssc-representation"&gt;official Jupyter Subprojects&lt;/a&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ipython/"&gt;IPython&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyter/"&gt;Jupyter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyterlab/"&gt;JupyterLab&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyterhub/"&gt;JupyterHub&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/voila-dashboards/"&gt;Voilà&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyter-server/"&gt;Jupyter Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyter-widgets/"&gt;Jupyter Widgets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jupyter-xeus/"&gt;jupyter-xeus&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content><category term="GitHub"/><category term="security"/></entry><entry><title>Please don’t disable authentication in Jupyter servers</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2022/please-dont-disable-authentication-in-jupyter-servers/" rel="alternate"/><published>2022-04-05T09:50:00+00:00</published><updated>2022-04-05T09:50:00+00:00</updated><author><name>Min RK</name></author><id>tag:jasongrout.github.io,2022-04-05:/medium-archive/pelican/posts/2022/please-dont-disable-authentication-in-jupyter-servers/</id><summary type="html">&lt;p&gt;We are aware of ransomware attacks specifically targeting Jupyter servers.&lt;/p&gt;
</summary><content type="html">&lt;p&gt;We are aware of ransomware attacks &lt;a href="https://blog.aquasec.com/python-ransomware-jupyter-notebook"&gt;specifically targeting Jupyter servers&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;First off: we have no evidence of a vulnerability in Jupyter associated with the attack. The attacks appear to focus on Jupyter servers &lt;em&gt;with authentication disabled.&lt;/em&gt; That’s what this post is about: &lt;strong&gt;please don’t do that&lt;/strong&gt;!&lt;/p&gt;
&lt;p&gt;Jupyter servers are authenticated with a random token &lt;em&gt;by default,&lt;/em&gt; so you should be fine with the defaults. That default random token is regenerated on each server launch. If that random token is &lt;em&gt;inconvenient&lt;/em&gt; for you (there are plenty of situations where this is the case), &lt;strong&gt;the answer is not to disable auth&lt;/strong&gt;! More on that below.&lt;/p&gt;
&lt;p&gt;We wrote about this &lt;a href="/posts/2017/public-notebooks-and-security/"&gt;before&lt;/a&gt;, but it bears repeating:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Jupyter exposes arbitrary code execution and a shell. If folks gain access, they can do anything you can do. You aren’t just protecting your notebooks, you are protecting your &lt;em&gt;whole computer&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;People can find your notebook server&lt;/strong&gt; if it’s accessible on the Internet. If they locate your server and it has auth disabled, that’s game over, and appears to be what happened in the above ransomware event. Jupyter’s popular enough (yay) that folks are always looking (boo).&lt;/li&gt;
&lt;li&gt;If the generated token pattern is inconvenient for how you work, you can set a persistent token or password in configuration instead of retrieving the generated token on each server launch. Save this token or password in your password manager for safe keeping, and accessing your server will be just as convenient as auth being disabled.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you have an interactive prompt, you can run &lt;code&gt;jupyter server password&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="err"&gt;$&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;jupyter&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt;
&lt;span class="n"&gt;Enter&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;password&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="err"&gt;🔐&lt;/span&gt;
&lt;span class="n"&gt;Verify&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nl"&gt;password&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="err"&gt;🔐&lt;/span&gt;
&lt;span class="o"&gt;[&lt;/span&gt;&lt;span class="n"&gt;JupyterPasswordApp&lt;/span&gt;&lt;span class="o"&gt;]&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;Wrote&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;hashed&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;to&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;~/&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;jupyter&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;jupyter_server_config&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;json&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;which generates and stores config that looks like:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;{
  &amp;quot;ServerApp&amp;quot;: {
    &amp;quot;password&amp;quot;: &amp;quot;argon2:$argon2id$v=19$m=10240,t=10,p=8$aFE/DuLj//6oGF2PHWy2DQ$eXHn6AbJe8Lryl4z9oGvMtZhX7iEdt41m+mhvyDvw88&amp;quot;
  }
}
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This is a &lt;em&gt;hashed, salted&lt;/em&gt; form of your password. We can’t get the password out of this, but we can use it to check if you typed it correctly on the login page. If an interactive prompt isn’t available to you (e.g. a cloud vm that starts the notebook server automatically), you can run this command on any machine, and copy the resulting config file to the destination machine as part of setup.&lt;/p&gt;
&lt;p&gt;If it works better for you, you can also generate &lt;em&gt;just&lt;/em&gt; the hashed password:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;jupyter_server.auth&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;passwd&lt;/span&gt;
&lt;span class="n"&gt;hashed_password&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;passwd&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;my-great-passphrase&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# just the &amp;quot;argon2:...&amp;quot;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;and get that into your config files, as best suits your needs. For example, in &lt;code&gt;~/.jupyter/jupyter_server_config.py&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;c.ServerApp.password = &amp;quot;argon2:...&amp;quot;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;or the same config in &lt;code&gt;~/.jupyter/jupyter_server_config.json&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;{
  &amp;quot;ServerApp&amp;quot;: {
    &amp;quot;password&amp;quot;: &amp;quot;argon2:...&amp;quot;
  }
}
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Read more details in &lt;a href="/posts/2017/public-notebooks-and-security/"&gt;our earlier post&lt;/a&gt;, and &lt;a href="https://jupyter-server.readthedocs.io/en/latest/operators/security.html"&gt;security documentation&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Please contact security@ipython.org if you have a vulnerability to report.&lt;/p&gt;
</content><category term="security"/></entry><entry><title>Trusted CI Cybersecurity Engagement with Jupyter</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2021/trusted-ci-cybersecurity-engagement-with-jupyter/" rel="alternate"/><published>2021-09-15T18:09:00+00:00</published><updated>2021-09-15T18:09:00+00:00</updated><author><name>Rollin Thomas</name></author><id>tag:jasongrout.github.io,2021-09-15:/medium-archive/pelican/posts/2021/trusted-ci-cybersecurity-engagement-with-jupyter/</id><summary type="html">&lt;p&gt;Trusted CI is the US National Science Foundation Cybersecurity Center of Excellence, staffed by cybersecurity experts who have spent…&lt;/p&gt;
</summary><content type="html">&lt;p&gt;&lt;a href="https://www.trustedci.org/about"&gt;Trusted CI&lt;/a&gt; is the US National Science Foundation Cybersecurity Center of Excellence, staffed by cybersecurity experts who have spent decades working with science and engineering communities and who have established track records in terms of usable, high-quality solutions suited to the needs of those communities. The team draws from best operational practices and includes leaders in the research and development of new methodologies and high-quality implementations. In addition to providing leadership, education, outreach, and training to raise the state of security practice across the sciences, Trusted CI undertakes one-on-one engagements with projects to address their cybersecurity challenges.&lt;/p&gt;
&lt;p&gt;As a part of &lt;a href="/posts/2021/jupyter-role-in-chaosdb/"&gt;timely&lt;/a&gt;, broader efforts to make Project Jupyter more responsive and proactive to security, the new &lt;a href="https://discourse.jupyter.org/t/project-jupyter-security-subproject/10175/6"&gt;security&lt;/a&gt; &lt;a href="https://github.com/jupyter/security"&gt;sub-project&lt;/a&gt; this past summer has undertaken a one-on-one engagement with Trusted CI to run through the end of 2021. This Trusted CI engagement was originally motivated by an upcoming Jupyter Security Best Practices Workshop funded by NumFOCUS as part of the Community Workshop series. The workshop is tentatively scheduled to be held April 2022 at the Ohio Supercomputer Center.&lt;/p&gt;
&lt;p&gt;The goals of the engagement between Project Jupyter and Trusted CI include the following tasks:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Review existing Jupyter deployment documentation related to security, identify gaps, and create recommendations for improvements.&lt;/li&gt;
&lt;li&gt;Identify Jupyter deployment use-cases as targets for Jupyter Security Best Practices documentation. Example use-cases include supercomputing centers, campus research clusters, workshops, small scientific projects, etc. Prioritize these use-cases based on which audiences would benefit most from new security documentation.&lt;/li&gt;
&lt;li&gt;Write Jupyter Security Best Practices documentation for high priority use-cases identified above. Work through other use-cases as time permits.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The Jupyter Security Best Practices documentation produced by this engagement will be shared with Project Jupyter for inclusion in their documentation, and also presented at the workshop.&lt;/p&gt;
&lt;p&gt;Here’s how you can get involved and learn more:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The security working group meets &lt;a href="https://jupyter.readthedocs.io/en/latest/community/content-community.html"&gt;every other Friday&lt;/a&gt;. You can follow and open issues the repository &lt;a href="https://github.com/jupyter/security"&gt;for public questions and meeting minutes&lt;/a&gt;. At this weeks meeting, our Trusted CI colleagues presented an evolving census of all Jupyter-related security documentation: Watch for an upcoming &lt;a href="https://discourse.jupyter.org/c/special-topics/security/48"&gt;Discourse&lt;/a&gt; post about it!&lt;/li&gt;
&lt;li&gt;As always, you can send your questions and concerns about security to &lt;a href="mailto:security@ipython.org"&gt;security@ipython.org&lt;/a&gt; to reach out to our security team.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We always welcome feedback, questions, and help regarding security in Jupyter. Here is a link to the original Trusted CI blog post that this blog post was based upon (with permission):&lt;/p&gt;
&lt;p&gt;&lt;a href="https://blog.trustedci.org/2021/08/engagement-with-jupyter.html"&gt;https://blog.trustedci.org/2021/08/engagement-with-jupyter.html&lt;/a&gt;&lt;/p&gt;
</content><category term="security"/></entry><entry><title>Jupyter’s role in #ChaosDB</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2021/jupyter-role-in-chaosdb/" rel="alternate"/><published>2021-09-01T21:43:00+00:00</published><updated>2021-09-02T06:56:00+00:00</updated><author><name>M Bussonnier</name></author><id>tag:jasongrout.github.io,2021-09-01:/medium-archive/pelican/posts/2021/jupyter-role-in-chaosdb/</id><summary type="html">&lt;p&gt;On August 26 it was revealed that a misconfiguration in Microsoft’s internal deployment of CosmosDB using Jupyter would allow attackers to…&lt;/p&gt;
</summary><content type="html">&lt;p&gt;On August 26 it &lt;a href="https://www.wiz.io/blog/chaosdb-how-we-hacked-thousands-of-azure-customers-databases"&gt;was revealed&lt;/a&gt; that a misconfiguration in Microsoft’s &lt;a href="https://msrc-blog.microsoft.com/2021/08/27/update-on-vulnerability-in-the-azure-cosmos-db-jupyter-notebook-feature/"&gt;internal deployment of CosmosDB&lt;/a&gt; using Jupyter would allow attackers to access all customer data. Fortunately, they report no evidence that customer data was compromised.&lt;/p&gt;
&lt;p&gt;Nonetheless, articles onlines, like &lt;a href="https://arstechnica.com/information-technology/2021/08/worst-cloud-vulnerability-you-can-imagine-discovered-in-microsoft-azure/"&gt;Ars Technica’s&lt;/a&gt; and &lt;a href="https://www.reuters.com/article/us-microsoft-security/researchers-cybersecurity-agency-urge-action-by-microsoft-cloud-database-users-idUSKBN2FT0K8"&gt;Reuter’s&lt;/a&gt; have strong headlines associated Jupyter, for example “Worst cloud vulnerability you can imagine.”&lt;/p&gt;
&lt;p&gt;This can be especially alarming for our community as no details on the vulnerability have been released yet, and members of our community wonder about Jupyter’s possible role in this vulnerability.&lt;/p&gt;
&lt;h2 id="what-the-jupyter-team-knows"&gt;What the Jupyter team knows&lt;/h2&gt;
&lt;p&gt;We learned about the CosmoDB vulnerability at the same time as everyone else; we had no prior notice, and received no privileged communication about this issue. We have not seen any evidence suggesting this relates to a vulnerability in Jupyter itself, as opposed to a misconfiguration of Microsoft’s internal services.&lt;/p&gt;
&lt;p&gt;We also had no prior interaction with the Microsoft team about their internal Jupyter deployment in CosmoDB.&lt;/p&gt;
&lt;p&gt;From the descriptions posted by &lt;a href="https://www.wiz.io/blog/chaosdb-how-we-hacked-thousands-of-azure-customers-databases"&gt;Wiz&lt;/a&gt; and &lt;a href="https://msrc-blog.microsoft.com/2021/08/27/update-on-vulnerability-in-the-azure-cosmos-db-jupyter-notebook-feature/"&gt;Microsoft&lt;/a&gt;, there is no suggestion of any vulnerability in Jupyter itself, and rather expect that Jupyter was used as convenient shell to exploit a vulnerability in the configuration of Microsoft’s internal services, but we have no information beyond what is publicly available to support that claim.&lt;/p&gt;
&lt;h2 id="what-are-we-doing-internally"&gt;What are we doing internally&lt;/h2&gt;
&lt;p&gt;Even if Jupyter does not have a vulnerability to fix, it is often possible for us to warn end users when risky configurations options are set. For example, if you try to login to JupyterHub over a non https connections, you will a see a warning.&lt;/p&gt;
&lt;figure&gt;
&lt;img alt="JupyterHub warning about login over unsecured HTTP" src="https://jasongrout.github.io/medium-archive/pelican/posts/2021/jupyter-role-in-chaosdb/images/001-1_v0isW10uaM0t1DyKOIL02Q.webp" loading="lazy" data-body-image=""&gt;
&lt;figcaption&gt;JupyterHub warning about login over unsecured HTTP&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;We are preparing for the full information release of #ChaosDB details, to see if there are any relevant safeguards and warnings to implement on the Jupyter side. We are also trying to reach the involved Microsoft Security Team personally to know whether there are steps we can take before public disclosure.&lt;/p&gt;
&lt;p&gt;In the meantime you can contribute and get involved:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The security working group meets &lt;a href="https://jupyter.readthedocs.io/en/latest/community/content-community.html"&gt;every other Friday&lt;/a&gt;. You can follow and open issues the repository &lt;a href="https://github.com/jupyter/security"&gt;for public questions and meeting minutes&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;You can send your questions and concerns about security to &lt;a href="mailto:security@ipython.org"&gt;security@ipython.org&lt;/a&gt; to reach out to our security team.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We always welcome feedback, questions, and help regarding security in Jupyter.&lt;/p&gt;
</content><category term="security"/></entry><entry><title>CVE-2021–32797 and CVE-2021–32798 Remote Code execution in JupyterLab and Jupyter Notebook</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2021/cve-2021-32797-and-cve-2021-32798-remote-code-execution/" rel="alternate"/><published>2021-08-09T20:05:00+00:00</published><updated>2021-08-09T20:19:00+00:00</updated><author><name>M Bussonnier</name></author><id>tag:jasongrout.github.io,2021-08-09:/medium-archive/pelican/posts/2021/cve-2021-32797-and-cve-2021-32798-remote-code-execution/</id><summary type="html">&lt;p&gt;TL:DR; All recent JupyterLab and Notebook versions are susceptible to a attack where a maliciously crafted notebook can trigger arbitrary…&lt;/p&gt;
</summary><content type="html">&lt;p&gt;TL:DR; All recent JupyterLab and Notebook versions are susceptible to a attack where a maliciously crafted notebook can trigger arbitrary code execution when a user views these malicious files.&lt;/p&gt;
&lt;p&gt;We strongly advise all users to deploy the new version of JupyterLab and Jupyter Notebook.&lt;/p&gt;
&lt;p&gt;Jupyter Notebook 6.4.1 or above, 5.7.11 or above.&lt;/p&gt;
&lt;p&gt;Jupyter Lab 3.1.4 or above, 3.0.17 or above, 2.3.2 or above, 2.2.10 or above , 1.2.21 or above&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;This blog post will be updated with links to the various patches, exploit and disclosure later once the final links are available&lt;/strong&gt;.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="jupyter-security-model"&gt;Jupyter Security Model&lt;/h2&gt;
&lt;p&gt;Jupyter Notebook act as a REPL (Read Eval Print Loop) in a browser, our main goal is to expose as many functionalities to our users, with the least restrictions. We also want users to be able to share their results with other, and let everyone be capable of reproducing the result.&lt;/p&gt;
&lt;p&gt;When receiving an untrusted notebook from a potentially malicious source we still want users to be able to inspect a notebook without risks, our approach is that an untrusted notebook has restrictive capabilities until all cells have been manually inspected and explicitly run by a user, or the notebook is explicitly marked as trusted. If one finds a way to bypass this trust mechanism, a notebook might be able to execute code in the browser at at a time where a user is not expecting execution to occur.&lt;/p&gt;
&lt;p&gt;This is what happen in these particular CVEs, where some content of a notebook were improperly handled.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;[This part of the blog post will be updated with links to actual reports, and proof of concept once the patched version have reached enough package repositories]&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="cve-timeline"&gt;&lt;strong&gt;CVE Timeline&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;We want to thanks Guillaume Jeanne (Google), and Timo Schmid (Google) for the vulnerability report and helping us through the fixing process.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Thursday, 15 Jul 2021 07:11:13 -0700 (PDT): Initial question about security issue disclosure on security@ipython.org (no specific on the vulnerability)&lt;/li&gt;
&lt;li&gt;Tuesday, 20 Jul 2021 05:52:09 -0700 (PDT): Actual Vulnerability Report.&lt;/li&gt;
&lt;li&gt;Tuesday, 20 Jul 2021 : Open relevant GitHub security advisory on &lt;a href="https://github.com/jupyter/notebook/security/advisories/GHSA-hwvq-6gjx-j797"&gt;Notebook&lt;/a&gt; and &lt;a href="https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-4952-p58q-6crx"&gt;JupyterLab&lt;/a&gt; Repositories&lt;/li&gt;
&lt;li&gt;Thursday, 5 August 2021 : First releases with patched version on PyPI.&lt;/li&gt;
&lt;li&gt;Monday, 9 August : publication of this blog post and publish security advisory on GitHub.&lt;/li&gt;
&lt;li&gt;[Further item may be added to list publication by downstream repositories, like conda, conda-forge, debian…, contact us to add an item]&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="what-we-learned"&gt;&lt;strong&gt;What we learned&lt;/strong&gt;&lt;/h2&gt;
&lt;p&gt;Dealing with Security vulnerability in Jupyter and more generally in Open-Source is far from easy. We initially thought about treating the Notebook and Lab CVE separately but they are/were too similar and the cross discussion too revealing to treat both independently.&lt;/p&gt;
&lt;p&gt;As Jupyter is mostly a volunteer based organisation, there is often no contributor responsible to replying to security issues, and when someone steps up they might not be a expert, nor available all the time. I want to give special thanks to &lt;a href="https://github.com/blink1073"&gt;Steve Silvester&lt;/a&gt; (Apple) , &lt;a href="https://github.com/afshin"&gt;Afshin Darian&lt;/a&gt; (Two Sigma), and &lt;a href="https://github.com/Zsailer"&gt;Zach Sailer&lt;/a&gt; (Apple), and &lt;a href="https://github.com/Carreau"&gt;Matthias Bussonnier&lt;/a&gt; (Quansight) for writing the fixes, planning through the release and notifying stakeholders.&lt;/p&gt;
&lt;p&gt;Advance notice to stakeholder is complicated, we know of a few large deployment and have personal connections to a couple organisation, and were able to reached out to let them know critical release would be published. There is an inherent tension between publicly warning our user base that security release would be published, which might push malicious actor to closely survey the codebase changes and re-derive the attack vectors, and publishing the release first, with the details later. Especially since we are trying to be transparent in our communication, security fixes are the opposite of our normal communication workflow.&lt;/p&gt;
&lt;p&gt;Our communication process is imperfect. We have 2 mailing list for security-related discussion. The first one – security@ipython.org – has only a couple of members all core contributors and can receive email from the outside, it is used for triage. It receive a high number of spam as this is public email. As it has only a few members and we are all busy, mail can slip through. The second mailing list is slightly larger, and used for internal announcement for stakeholder. It has a fairly open membership model, (ask a Jupyter developer if you can be on it, and the reason why and we’ll likely add you), though it’s content seem to be ignored (it even lands on my spam folder, not sure why).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What we’ll do better&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;In order to attempt to better react and be proactive with respect to security we &lt;a href="https://github.com/jupyter/governance/issues/111"&gt;are&lt;/a&gt; attempting &lt;a href="https://discourse.jupyter.org/t/project-jupyter-security-subproject/10175/6"&gt;to form&lt;/a&gt; and new &lt;a href="https://github.com/jupyter/security"&gt;security-focused&lt;/a&gt; subproject/workgroup to educate and have procedure for everything security related. We welcome your involvement and feedback in how to improve Jupyter security and how to better involve the community.&lt;/p&gt;
</content><category term="Jupyter Notebook"/><category term="JupyterLab"/><category term="releases"/><category term="security"/></entry><entry><title>Open Redirect Vulnerability in Jupyter notebook, JupyterHub</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2019/open-redirect-vulnerability-in-jupyter-jupyterhub/" rel="alternate"/><published>2019-03-28T14:03:00+00:00</published><updated>2019-04-01T11:20:00+00:00</updated><author><name>Min RK</name></author><id>tag:jasongrout.github.io,2019-03-28:/medium-archive/pelican/posts/2019/open-redirect-vulnerability-in-jupyter-jupyterhub/</id><summary type="html">&lt;p&gt;JupyterHub ≤ 0.9.4 and Notebook ≤ 5.7.6 are affected. Versions 0.9.5 and 5.7.7 are released today with fixes. Upgrade with pip or conda:&lt;/p&gt;
</summary><content type="html">&lt;p&gt;&lt;strong&gt;Update: notebook 5.7.7 and JupyterHub 0.9.5 contained incomplete fixes for this issue. 5.7.8 and 0.9.6 are released with more complete fixes.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;JupyterHub ≤ 0.9.5 and Notebook ≤ 5.7.8 are affected. Versions 0.9.6 and 5.7.8 are released with fixes. Upgrade with pip or conda:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;pip install --upgrade &amp;#39;notebook&amp;gt;=5.7.8&amp;#39;
pip install --upgrade &amp;#39;jupyterhub&amp;gt;=0.9.6&amp;#39;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;conda install -c conda-forge &amp;#39;notebook&amp;gt;=5.7.8&amp;#39;
conda install -c conda-forge &amp;#39;jupyterhub&amp;gt;=0.9.6&amp;#39;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;notebook 5.7.8 also fixes some compatibility issues and regressions introduced in 5.7.5 and 5.7.6, especially on some Windows systems. If you use the &lt;a href="https://zero-to-jupyterhub.readthedocs.io"&gt;jupyterhub helm chart&lt;/a&gt;, version 0.8.2 upgrades JupyterHub to 0.9.6.&lt;/p&gt;
&lt;h2 id="what-is-an-open-redirect-vulnerability"&gt;What is an Open Redirect Vulnerability?&lt;/h2&gt;
&lt;p&gt;Login pages tend to take a parameter for redirecting back to a page after successful login, e.g. &lt;code&gt;/login?next=/notebooks/mynotebook.ipynb&lt;/code&gt;, so that you aren’t disrupted too much if you try to visit a page, but have to authenticate first. An &lt;a href="https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.md"&gt;Open Redirect Vulnerability&lt;/a&gt; is when a malicious person crafts a link pointing to the login page of a trusted site, but setting the “redirect after successful login” parameter to send the user to their own site, instead of a page on the authenticated site (the notebook or JupyterHub server), e.g. &lt;code&gt;/login?next=http://badwebsite.biz&lt;/code&gt;. This doesn’t necessarily compromise anything immediately, but it enables phishing if users don’t notice that the domain has changed, e.g. by showing a fake “re-enter your password” page. Servers generally have to validate the redirect URL to avoid this. Both JupyterHub and Notebook already do this, but the validation didn’t take into account all possible ways to redirect to other sites, so some malicious URLs could still be crafted to redirect away from the server (the above example does not work in any recent version of either package). Only certain browsers (Chrome and Firefox, not Safari) could be redirected from the JupyterHub login page, but all browsers could be redirected away from a standalone notebook server.&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned CVE-2019–10255. This post will be updated when it has been assigned. Thanks to Ronak Odhaviya for reporting the issue. You can report security issues by emailing &lt;a href="mailto:ipython-security@googlegroups.com"&gt;ipython-security@googlegroups.com&lt;/a&gt;.&lt;/p&gt;
</content><category term="Jupyter Notebook"/><category term="JupyterHub"/><category term="security"/></entry><entry><title>Jupyter notebook XSSI security fix</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2019/jupyter-notebook-xssi-security-fix/" rel="alternate"/><published>2019-03-09T20:46:00+00:00</published><updated>2019-03-09T20:46:00+00:00</updated><author><name>Min RK</name></author><id>tag:jasongrout.github.io,2019-03-09:/medium-archive/pelican/posts/2019/jupyter-notebook-xssi-security-fix/</id><summary type="html">&lt;p&gt;We have just released Jupyter notebook 5.7.6 with a security fix for a cross-site inclusion (XSSI) vulnerability, where content from a…&lt;/p&gt;
</summary><content type="html">&lt;p&gt;We have just released Jupyter notebook 5.7.6 with a security fix for a cross-site inclusion (&lt;a href="https://www.scip.ch/en/?labs.20160414"&gt;XSSI&lt;/a&gt;) vulnerability, where content from a Jupyter server could be included in another page if the visitor is logged in to the Jupyter server and the author of the page knows the URL of the server and the path within the server’s notebook directory that they would like to include. Further, it has been demonstrated with the Internet Explorer browser that some content from the accessed file can be retrieved by the attacking page. This has not yet been demonstrated with other browsers, however.&lt;/p&gt;
&lt;p&gt;To upgrade:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;pip install --upgrade &amp;#39;notebook&amp;gt;=5.7.6&amp;#39;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;or conda:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;conda install &amp;#39;notebook&amp;gt;=5.7.6&amp;#39;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This vulnerability was reported by the HackerOne hacker Abhishek Bundela, via Jonathan Kamens at Quantopian. The patch was developed by Min Ragan-Kelley with help from Devdatta Akhawe. Jupyter is grateful to Quantopian’s bug bounty program, which has found and reported this and other security flaws in Jupyter.&lt;/p&gt;
&lt;p&gt;This vulnerability has been assigned CVE-2019–9644.&lt;/p&gt;
</content><category term="Jupyter Notebook"/><category term="security"/></entry><entry><title>Jupyter Notebook security fixes</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2018/jupyter-notebook-security-fixes/" rel="alternate"/><published>2018-11-19T22:20:00+00:00</published><updated>2018-11-19T22:20:00+00:00</updated><author><name>Min RK</name></author><id>tag:jasongrout.github.io,2018-11-19:/medium-archive/pelican/posts/2018/jupyter-notebook-security-fixes/</id><summary type="html">&lt;p&gt;Two security issues have been found and fixed this week, where untrusted javascript could be executed if malicious files could be…&lt;/p&gt;
</summary><content type="html">&lt;p&gt;Two security issues have been found and fixed this week, where untrusted javascript could be executed if malicious files could be delivered to the users system and the user takes specific actions with those malicious files.&lt;/p&gt;
&lt;p&gt;The first allowed nbconvert endpoints (such as Print Preview) to render untrusted HTML and javascript with access to the notebook server. This is fixed in notebook 5.7.1. All notebook versions prior to 5.7.1 are affected. Thanks to Jonathan Kamens of Quantopian for reporting. This issue has been assigned CVE-2018–19351.&lt;/p&gt;
&lt;p&gt;The second issue allowed maliciously crafted directory names to execute javascript when opened in the tree view. This is fixed in notebook 5.7.2. All versions of notebook from 5.3.0 to 5.7.1 are affected. Thanks to Marvin Solano Quesada for reporting. This issue has been assigned CVE-2018–19352.&lt;/p&gt;
&lt;p&gt;You can check your version of the notebook package by issuing the following command:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;jupyter notebook --version&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Whether you are using classic notebook, JupyterLab or any other notebook server extensions, we recommend that you update the &lt;code&gt;notebook&lt;/code&gt; package with :&lt;/p&gt;
&lt;p&gt;&lt;code&gt;pip install --upgrade notebook&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;or if you are using conda-forge&lt;/p&gt;
&lt;p&gt;&lt;code&gt;conda upgrade notebook&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Thanks especially to Jonathan and Marvin for reporting these issues! If you find a security issue in a Jupyter project, please report it to &lt;code&gt;security@ipython.org&lt;/code&gt;.&lt;/p&gt;
</content><category term="Jupyter Notebook"/><category term="security"/></entry><entry><title>Security fix for Jupyter Notebook</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2018/security-fix-for-jupyter-notebook/" rel="alternate"/><published>2018-07-18T04:31:00+00:00</published><updated>2018-08-16T17:33:00+00:00</updated><author><name>Min RK</name></author><id>tag:jasongrout.github.io,2018-07-18:/medium-archive/pelican/posts/2018/security-fix-for-jupyter-notebook/</id><summary type="html">&lt;p&gt;We have just released Jupyter Notebook 5.6.0. This release fixes a vulnerability that could allow a maliciously crafted notebook to execute…&lt;/p&gt;
</summary><content type="html">&lt;p&gt;We have just released Jupyter Notebook 5.6.0. This release fixes a vulnerability that could allow a maliciously crafted notebook to execute JavaScript when it is opened, bypassing the trusted-notebook mechanism.&lt;/p&gt;
&lt;p&gt;We recommend updating the notebook immediately, via pip:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;pip install notebook&amp;gt;=5.6.0&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;or conda:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;conda install notebook&amp;gt;=5.6.0&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected versions&lt;/strong&gt;: all releases prior to 5.6.0&lt;/p&gt;
&lt;p&gt;JupyterLab users are affected, independent of the version of JupyterLab itself. Upgrading the notebook package to 5.6.0 resolves the issue for users of both JupyterLab and the classic notebook.&lt;/p&gt;
&lt;p&gt;A CVE has been requested for the vulnerability. Release notes for 5.6.0 and this post will be updated as the CVE is assigned. More details of the vulnerability will be released in 30 days, on August 16, 2018.&lt;/p&gt;
&lt;p&gt;Security reports for Jupyter are greatly appreciated. You can &lt;a href="http://jupyter-notebook.readthedocs.io/en/stable/security.html#reporting-security-issues"&gt;report security issues&lt;/a&gt; to security@ipython.org.&lt;/p&gt;
&lt;p&gt;Thanks to Jonathan Kamens for reporting this issue to the security list.&lt;/p&gt;
&lt;p&gt;[Update July 28] The vulnerability have been assigned number CVE-2018–1999024.&lt;/p&gt;
&lt;p&gt;[Update August 16] MathJax versions prior to version 2.7.4 contains a Cross Site Scripting (XSS) vulnerability in the \unicode{} macro that can result in potentially untrusted Javascript running within a web browser, for example at notebook load. Notebook 5.6.0 ships with an updated mathjax version 2.7.4 which fixes this vulnerability.&lt;/p&gt;
</content><category term="Jupyter Notebook"/><category term="security"/></entry><entry><title>Security fix for JupyterHub GitLab OAuthenticator Group Whitelists</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2018/security-fix-for-jupyterhub-gitlab-oauthenticator/" rel="alternate"/><published>2018-02-16T22:12:00+00:00</published><updated>2018-03-16T15:15:00+00:00</updated><author><name>Min RK</name></author><id>tag:jasongrout.github.io,2018-02-16:/medium-archive/pelican/posts/2018/security-fix-for-jupyterhub-gitlab-oauthenticator/</id><summary type="html">&lt;p&gt;This vulnerability has been assigned CVE-2018–7206&lt;/p&gt;
</summary><content type="html">&lt;p&gt;This vulnerability has been assigned CVE-2018–7206&lt;/p&gt;
&lt;p&gt;If you are using JupyterHub with the GitLab OAuthenticator and its gitlab_group_whitelist support, there is a security issue where the authenticator will allow users outside your intended group whitelist to create accounts. A fix has been released as OAuthenticator 0.6.2 and 0.7.3. No other authentication mechanism, including GitLabOAuthenticator without using the group whitelist feature, is affected. If you are using GitLab authentication with group whitelist support, upgrade oauthenticator immediately:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;python3 -m pip install --upgrade oauthenticator
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Thanks to Joseph Weston for reporting the issue and providing the fix.&lt;/p&gt;
&lt;p&gt;Timeline (all times UTC):&lt;/p&gt;
&lt;p&gt;2018–02–16 09:51 Joseph Weston reports security issue to the Jupyter security list&lt;/p&gt;
&lt;p&gt;2018–02–16 16:08 Fix is verified and applied to oauthenticator master&lt;/p&gt;
&lt;p&gt;2018–02–16 21:52 oauthenticator 0.7.3 and 0.6.2 are released with the fix&lt;/p&gt;
&lt;p&gt;2018–02–18 03:02 CVE-2018–7206 assigned&lt;/p&gt;
</content><category term="JupyterHub"/><category term="security"/></entry><entry><title>Public Notebooks and Security</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2017/public-notebooks-and-security/" rel="alternate"/><published>2017-11-28T19:33:00+00:00</published><updated>2017-11-28T19:33:00+00:00</updated><author><name>Min RK</name></author><id>tag:jasongrout.github.io,2017-11-28:/medium-archive/pelican/posts/2017/public-notebooks-and-security/</id><summary type="html">&lt;p&gt;tl;dr: don’t disable notebook authentication!&lt;/p&gt;
</summary><content type="html">&lt;p&gt;&lt;em&gt;tl;dr: don’t disable notebook authentication!&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Let’s chat a little bit about public Jupyter notebook servers and security. A lot of folks run notebook servers that are publicly accessible, whether they are the access point to a cloud server or remote access to their home or office computer. This is great! It is important to keep in mind that, since arbitrary code execution is the main point of IPython and Jupyter, running a publicly accessible server without authentication or encryption is a very bad idea indeed. Prior to notebook 4.3, this was the &lt;em&gt;default&lt;/em&gt; behavior of Jupyter, which has led to a lot of insecure notebook servers running on cloud services. One aspect that may not be apparent is that &lt;strong&gt;people can find your public notebook server&lt;/strong&gt;, especially if it is on one of the popular cloud providers. Systematic port scans will turn up notebook servers, especially for those running on the default port of 8888. And Jupyter has become popular enough (🎉) that we know people are doing this (😠). &lt;strong&gt;Running a publicly accessible notebook server without authentication is making your computing resources free for the world to use.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The highlights to keep in mind:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Always enable a password or token for publicly accessible notebook servers (this includes shared computers)&lt;/li&gt;
&lt;li&gt;Use HTTPS for authenticated notebooks over the Internet&lt;/li&gt;
&lt;li&gt;Unsecured public notebook servers are discoverable&lt;/li&gt;
&lt;li&gt;Running on a cloud service should be treated as if it’s publicly accessible&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The first two points shouldn’t be new information, and anyone &lt;a href="https://jupyter-notebook.readthedocs.io/en/latest/public_server.html#running-a-public-notebook-server"&gt;following the documentation&lt;/a&gt; should be adding basic authentication when exposing a server to the public. If you are already accessing a notebook server over https with a password or token, you have nothing to worry about. However, if you are running unsecured notebook servers on the Internet, please stop and &lt;a href="http://jupyter-notebook.readthedocs.io/en/latest/public_server.html#securing-a-notebook-server"&gt;enable a password&lt;/a&gt;. The latter points are important and may not be obvious, but the gist is: don’t disable notebook authentication, even if you think your bases are covered via other means.&lt;/p&gt;
&lt;p&gt;In notebook 4.3, a token is enabled by default, making it a little bit more inconvenient to run a totally insecure notebook server. We can’t feasibly require HTTPS by default, but free, trusted HTTPS has never been easier, thanks to &lt;a href="https://letsencrypt.org/"&gt;LetsEncrypt&lt;/a&gt;. If you can’t assign a domain name to your server, self-signed certificates &lt;a href="http://jupyter-notebook.readthedocs.io/en/latest/public_server.html#using-ssl-for-encrypted-communication"&gt;can be used&lt;/a&gt;, with some caveats (notably: Safari requires self-signed certificates be trusted at the system level before it will allow websocket connections). For shared deployments, you can also use &lt;a href="https://jupyterhub.readthedocs.io"&gt;JupyterHub&lt;/a&gt;, which allows you to authenticate notebooks via the system (PAM) or OAuth providers such as GitHub, Google, etc.&lt;/p&gt;
&lt;p&gt;Be safe out there.&lt;/p&gt;
</content><category term="Jupyter Notebook"/><category term="security"/></entry><entry><title>Security release: Jupyter Notebook 4.3.1</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2016/security-release-jupyter-notebook-4-3-1/" rel="alternate"/><published>2016-12-22T02:25:00+00:00</published><updated>2017-08-28T18:20:00+00:00</updated><author><name>Project Jupyter</name></author><id>tag:jasongrout.github.io,2016-12-22:/medium-archive/pelican/posts/2016/security-release-jupyter-notebook-4-3-1/</id><summary type="html">&lt;p&gt;We have just released Jupyter Notebook 4.3.0 and 4.3.1 with some important security fixes. You can check out the changelog for more details on the many fixes …&lt;/p&gt;
</summary><content type="html">&lt;p&gt;We have just released Jupyter Notebook 4.3.0 and 4.3.1 with some important security fixes.&lt;/p&gt;
&lt;p&gt;You can check out &lt;a href="https://jupyter-notebook.readthedocs.io/en/stable/changelog.html#release-4-3-1"&gt;the changelog&lt;/a&gt; for more details on the many fixes and improvements. I’m going to focus on the security changes in this post.&lt;/p&gt;
&lt;h3 id="430-token-authentication"&gt;4.3.0: Token authentication&lt;/h3&gt;
&lt;p&gt;The biggest change in 4.3 is the addition of token-based authentication, which is &lt;strong&gt;enabled by default&lt;/strong&gt;. Several of the security issues the notebook has had over the years would have been avoided if the notebook ran with authentication by default. We did not do this for a long time, because the process of enabling and entering a password on a localhost-only web application was deemed too cumbersome, and the risks too small, given that it listened only on localhost. With automatic token authentication, I think we have a solution that should be convenient enough for most users that we can now switch to enabling authentication by default.&lt;/p&gt;
&lt;p&gt;If you use Jupyter in its default configuration, which is to open your browser automatically when you type &lt;code&gt;jupyter notebook&lt;/code&gt;, this shouldn’t have much impact on your daily work. In this case, a one-time token is generated, and your browser opens with this in the URL. That token is immediately consumed, and your browser will be authenticated, storing the information in a cookie for future requests.&lt;/p&gt;
&lt;p&gt;If you access the notebook without authentication, you will see this page:&lt;/p&gt;
&lt;p&gt;&lt;img src="https://jasongrout.github.io/medium-archive/pelican/posts/2016/security-release-jupyter-notebook-4-3-1/images/g001-Screen-Shot-2016-12-20-at-16-13-37.webp" alt="" loading="lazy" data-body-image=""&gt;&lt;/p&gt;
&lt;p&gt;This may happen if you switch browsers, or use the notebook with the &lt;code&gt;--no-browser&lt;/code&gt; option, in which you will need to enter the token manually the first time you connect to a server with a given browser. This can be done at the login page above, or via a URL containing the token. The notebook server logs this URL when it starts, so you can paste the URL into your browser:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="k"&gt;[C 16:11:17.581 NotebookApp]&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="na"&gt;Copy/paste this URL into your browser when you connect for the first time,&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="na"&gt;to login with a token&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;
&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="na"&gt;http&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="s"&gt;//localhost:8888/?token=20abd368...&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;After you have logged in with this token just once, a cookie is set and used thereafter, even across restarts of the notebook server. So you shouldn’t need to deal with the token after the first time you have used the notebook on a given machine, until/unless you switch browsers or launch new notebook servers &lt;em&gt;on different ports&lt;/em&gt;. This does mean that cookies are required for authenticated access to notebooks, and clearing cookies means needing to login again.&lt;/p&gt;
&lt;p&gt;At any time, you can see all of your current notebook servers with their token-authenticated URLs by running the &lt;code&gt;jupyter notebook list&lt;/code&gt; command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class="w"&gt; &lt;/span&gt;jupyter&lt;span class="w"&gt; &lt;/span&gt;notebook&lt;span class="w"&gt; &lt;/span&gt;list
Currently&lt;span class="w"&gt; &lt;/span&gt;running&lt;span class="w"&gt; &lt;/span&gt;servers:
http://localhost:8888/?token&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="m"&gt;1234&lt;/span&gt;...&lt;span class="w"&gt; &lt;/span&gt;::&lt;span class="w"&gt; &lt;/span&gt;/Users/you/notebooks
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;We didn’t communicate the information about token authentication very well in 4.3.0, and I apologize for that. 4.3.1 should make the token behavior much clearer, with more information in both the login form and the notebook log output about how to use the tokens and when you need them. You can see &lt;a href="http://jupyter-notebook.readthedocs.io/en/latest/security.html"&gt;the docs&lt;/a&gt; for more details. We’re always open to improvements, so please &lt;a href="https://github.com/jupyter/notebook/issues"&gt;open an Issue&lt;/a&gt; if you are having trouble.&lt;/p&gt;
&lt;h3 id="431"&gt;4.3.1&lt;/h3&gt;
&lt;p&gt;4.3.1 follows shortly after 4.3.0, with a fix for a CSRF vulnerability (&lt;strong&gt;CVE-2016–9971&lt;/strong&gt;), affecting users of the Firefox or Microsoft (IE, Edge) browsers, and any other browsers that do not set the Origin header on cross-site forms. WebKit and Blink based browsers like Safari and Chrome are not affected. The effect of this vulnerability is the ability of forms on malicious websites visited by the user to spawn new kernels and create empty, untitled files on the user’s notebook server. CORS protections already in place prevent further access to these kernels and editing the content of any files.&lt;/p&gt;
&lt;p&gt;Summary:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CVE-2016–9971&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Affected notebook versions:&lt;/strong&gt; all notebook releases &amp;lt; 4.3.1&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Affected users:&lt;/strong&gt; Users of Firefox or Microsoft browsers, or other browsers that do not set the Origin header on forms.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Results:&lt;/strong&gt; Visiting malicious pages with these browsers could result in unauthorized launch of new kernels or creation of empty, untitled files on the user’s notebook server&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Fix:&lt;/strong&gt; Upgrade to notebook-4.3.1, which uses an &lt;code&gt;xsrf&lt;/code&gt; token via cookies to validate the origin of forms. See &lt;a href="http://www.tornadoweb.org/en/stable/guide/security.html#cross-site-request-forgery-protection"&gt;tornado docs&lt;/a&gt; for details.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="update-practical-effects-of-xsrf-for-extensions"&gt;Update: practical effects of xsrf for extensions&lt;/h3&gt;
&lt;p&gt;This note was omitted when first posted.&lt;/p&gt;
&lt;p&gt;The use of the xsrf token affects existing extensions / etc. that work directly with the notebook server via REST API. To make requests to the rest API, the &lt;code&gt;_xsrf&lt;/code&gt; cookie must be sent back to the server in the &lt;code&gt;X-XSRF-Token&lt;/code&gt; header of API requests, for example:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="n"&gt;function&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;_get_cookie&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="o"&gt;//&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;tornado&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;docs&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="o"&gt;//&lt;/span&gt;&lt;span class="n"&gt;www&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tornadoweb&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;org&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;en&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;stable&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;guide&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="n"&gt;security&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;html&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;document&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;cookie&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="k"&gt;match&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s2"&gt;b&amp;quot;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;=([^;]*)&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s2"&gt;b&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;?&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;r&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;undefined&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="n"&gt;function&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;_add_xsrf_token&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="o"&gt;//&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;Adds&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;xsrf&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;token&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;header&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;to&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;jquery&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ajax&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;||&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{};&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;xsrf_token&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;_get_cookie&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;_xsrf&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;xsrf_token&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;headers&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="w"&gt;      &lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;headers&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{};&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;headers&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;X-XSRFToken&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;xsrf_token&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="n"&gt;function&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ajax&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="o"&gt;//&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;like&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;$.&lt;/span&gt;&lt;span class="n"&gt;ajax&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;but&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ensure&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;xsrf&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;token&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;is&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;added&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;to&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;headers&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;_add_xsrf_token&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;$.&lt;/span&gt;&lt;span class="n"&gt;ajax&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;url&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;settings&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;};&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This code will also work for any previous version of the notebook, where the xsrf cookie will be undefined and ignored.&lt;/p&gt;
&lt;p&gt;If you’re using &lt;code&gt;fetch&lt;/code&gt;, you’ll need to set &lt;code&gt;credentials: true&lt;/code&gt; as well so that the &lt;code&gt;Cookie&lt;/code&gt; header is set.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="k"&gt;var&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;xsrfToken&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;_get_cookie&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;_xsrf&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;fetch&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;http://127.0.0.1:8888/api/contents/&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="n"&gt;method&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;POST&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="n"&gt;credentials&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;include&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="n"&gt;headers&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;span class="w"&gt;      &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;X-XSRFToken&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;xsrfToken&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="w"&gt;      &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Content-Type&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;application/json&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;
&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="n"&gt;body&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Test.py&amp;quot;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
</content><category term="Jupyter Notebook"/><category term="releases"/><category term="security"/></entry><entry><title>ipywidget security release</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2016/ipywidget-security-release/" rel="alternate"/><published>2016-09-26T23:37:00+00:00</published><updated>2016-12-15T18:27:00+00:00</updated><author><name>Jupyter Team</name></author><id>tag:jasongrout.github.io,2016-09-26:/medium-archive/pelican/posts/2016/ipywidget-security-release/</id><summary type="html">&lt;p&gt;Hello Jovyan, A version of ipywidget has been released, which fixes important security issues. Please upgrade ipywidgets as soon as you can: $ pip install ipywidgets --upgrade Please do so in all your environments. More details follow. We requested a CVE number and were asked to wait before any public disclosure&lt;/p&gt;
</summary><content type="html">&lt;p&gt;Hello Jovyan,&lt;/p&gt;
&lt;p&gt;A version of ipywidget has been released, which fixes important security issues. Please upgrade ipywidgets as soon as you can:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class="w"&gt; &lt;/span&gt;pip&lt;span class="w"&gt; &lt;/span&gt;install&lt;span class="w"&gt; &lt;/span&gt;ipywidgets&lt;span class="w"&gt; &lt;/span&gt;--upgrade
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Please do so in all your environments.&lt;/p&gt;
&lt;p&gt;More details follow. We requested a CVE number and were asked to wait before any public disclosure of the vulnerability. As we have now been delaying the disclosure for over a resonable time, and we’re still waiting for the CVE number, we decided to still disclose the vulnerability. This post will be updated once/if a CVE number is made available.&lt;/p&gt;
&lt;p&gt;[Update Dec 15, 2016]&lt;/p&gt;
&lt;p&gt;A CVE number cannot be assigned for lack of sufficient information. No explanation of what more is needed was provided.&lt;/p&gt;
&lt;h1 id="description"&gt;Description&lt;/h1&gt;
&lt;p&gt;ipywidgets version 5.1.5 (widgetsnbextension 1.2.3) fixes a security vulnerability (CVE-PENDING) which affects the usage of ipywidgets in conjunction with the Jupyter Notebook.&lt;/p&gt;
&lt;h2 id="affected-versions"&gt;Affected versions&lt;/h2&gt;
&lt;p&gt;ipywidgets version 5.0.0 ≤ V ≤ 5.1.4 (widgetsnbextension &amp;lt; 1.2.3).&lt;/p&gt;
&lt;p&gt;Only users who installed ipywidgets using pip or from source on the GitHub repository are affected.&lt;/p&gt;
&lt;p&gt;Anaconda users are unaffected because the vulnerable version of ipywidget has never been released to the default conda channel.&lt;/p&gt;
&lt;h2 id="resolution"&gt;Resolution&lt;/h2&gt;
&lt;p&gt;We released ipywidgets version 5.1.5 (widgetsnbextension version 1.2.3).&lt;/p&gt;
&lt;p&gt;You can check whether your system is affected by running the following command from a Python or IPython prompt:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&lt;span class="o"&gt;&amp;gt;&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;distutils.version&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;LooseVersion&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;V&lt;/span&gt;
&lt;span class="o"&gt;&amp;gt;&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;ipywidgets&lt;/span&gt;
&lt;span class="o"&gt;&amp;gt;&amp;gt;&amp;gt;&lt;/span&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;V&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;5.0.0&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="n"&gt;V&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ipywidgets&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;__version__&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="n"&gt;V&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;5.1.5&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
        &lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;Upgrade ipywidgets to 5.1.5&amp;quot;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;If your system is vulnerable, you will see the following output:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;Upgrade ipywidgets to 5.1.5
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;If your system is vulnerable please upgrade to ipywidgets version 5.1.5. Use the following command to install:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class="w"&gt; &lt;/span&gt;pip&lt;span class="w"&gt; &lt;/span&gt;install&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;ipywidgets&amp;gt;=5.1.5&amp;quot;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;or&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;$&lt;span class="w"&gt; &lt;/span&gt;conda&lt;span class="w"&gt; &lt;/span&gt;install&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;quot;ipywidgets&amp;gt;=5.1.5&amp;quot;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;h1 id="technical-details"&gt;Technical details&lt;/h1&gt;
&lt;p&gt;The vulnerability was discovered following an investigation of a potential vulnerability reported by Brian Granger to the ipython-security mailing list (&lt;code&gt;security@ipython.org&lt;/code&gt;) on May 5.&lt;/p&gt;
&lt;p&gt;The reason for such behavior was determined on May 5 by Matthias Bussonnier.&lt;br&gt;
A fix was proposed written and reviewed, then &lt;a href="https://github.com/ipython/ipywidgets/pull/591"&gt;merged&lt;/a&gt; into the development branch on May 20, and a non vulnerable version released on May 25.&lt;/p&gt;
&lt;p&gt;A widget snapshotting feature introduced in ipywidgets 5.0.0 allowed untrusted javascript code to execute in an untrusted notebook on loading and saving of a notebook. A well crafted notebook could execute arbitrary code with the rights of the current user in the context of the page, the notebook server, and available kernels.&lt;/p&gt;
&lt;p&gt;We recommend immediate upgrade of the ipywidgets package.&lt;/p&gt;
&lt;p&gt;There is no simple configuration option that could mitigate the system for vulnerability. The user must upgrade to ipywidget version 5.1.5 or downgrade to 4.x.&lt;/p&gt;
&lt;h2 id="future-plan"&gt;Future Plan&lt;/h2&gt;
&lt;p&gt;The security issue resulted from the seemingly harmless combination of calls:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;json = cell.get_json()
json = update_json(json)
cell.clear_output()
cell.from_json(json)
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The &lt;code&gt;clear_output()&lt;/code&gt; method has as a consequence to mark the cell as trusted (as it has no output that can potentially execute javascript). This is followed by the next call which can trigger JavaScript execution in the page context.&lt;/p&gt;
&lt;p&gt;We plan on improving the notebook API so that &lt;code&gt;clear_output()&lt;/code&gt; does not change the trusted status of a cell (or a notebook), to prevent mistakes like this from having security consequences. This will lead to the slight behavior change that an empty cell with no output can be untrusted.&lt;/p&gt;
&lt;h2 id="doing-better-next-time"&gt;Doing better next time&lt;/h2&gt;
&lt;p&gt;We learned that we are not completely ready for fast release of security fixes. The time from vulnerability discovery to available fix and release could have been better. The announcement was delayed while waiting for a CVE number which is still not there. We will consider a sorter timescale to publication even if we don’t get assigned a CVE number quickly. The standard seem to be 90 days from security vulnerability report, we might end up selecting this as well.&lt;/p&gt;
&lt;p&gt;We encourage users who find possible security issues to notify &lt;code&gt;security@ipython.org&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
</content><category term="releases"/><category term="security"/><category term="widgets"/></entry><entry><title>Notebook 4.2.2: Security fix</title><link href="https://jasongrout.github.io/medium-archive/pelican/posts/2016/security-fix-notebook-4-2-2/" rel="alternate"/><published>2016-08-03T20:47:00+00:00</published><updated>2016-08-03T20:47:00+00:00</updated><author><name>Min RK</name></author><id>tag:jasongrout.github.io,2016-08-03:/medium-archive/pelican/posts/2016/security-fix-notebook-4-2-2/</id><summary type="html">&lt;p&gt;TL;DR: upgrade to notebook 4.2.2 We just released notebook 4.2.2 with a few bugfixes and one important security fix. We (specifically Steve Sylvester) have found a longstanding security issue in the Notebook, regarding output of untrusted notebooks being able to execute code when the notebook&lt;/p&gt;
</summary><content type="html">&lt;p&gt;&lt;strong&gt;TL;DR: upgrade to notebook 4.2.2&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;We just released notebook 4.2.2 with a &lt;a href="http://jupyter-notebook.readthedocs.io/en/stable/changelog.html#release-4-2-2"&gt;few bugfixes&lt;/a&gt; and one important security fix.&lt;/p&gt;
&lt;p&gt;We (specifically &lt;a href="https://github.com/blink1073"&gt;Steve Sylvester&lt;/a&gt;) have found a longstanding security issue in the Notebook, regarding output of untrusted notebooks being able to execute code when the notebook is opened.&lt;/p&gt;
&lt;p&gt;The vulnerability has been assigned the identifier CVE-2016-6524.&lt;/p&gt;
&lt;p&gt;Affected versions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.0 ≤ IPython &amp;lt; 4.0 (all IPython notebook versions, starting with the introduction of the concept of untrusted output)&lt;/li&gt;
&lt;li&gt;notebook ≤ 4.2.1&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Solution:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade to notebook 4.2.2&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Specifically:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;pip install --upgrade notebook&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;or &lt;code&gt;conda install notebook&lt;/code&gt; (once conda channels propagate the release)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you cannot upgrade to 4.2.2, we have prepared a backported patch for the &lt;a href="https://github.com/ipython/ipython/commit/61c99ede7d31c1f661fba351765cac0f92c07856"&gt;2.x&lt;/a&gt; and &lt;a href="https://github.com/ipython/ipython/commit/e2ba4d66a08ae06d42ba9085b8a75ab8c4fad27b"&gt;3.x&lt;/a&gt; branches of IPython, but have no current plans for making a new release of these branches.&lt;/p&gt;
&lt;h2 id="details"&gt;Details&lt;/h2&gt;
&lt;p&gt;The vulnerability was reported on July 26, and a fix proposed on the same day. After some review and testing of the patch and a check for similar vulnerabilities, on August 3 a CVE was assigned and the 4.2.2 release made immediately thereafter.&lt;/p&gt;
&lt;p&gt;The goal of Jupyter notebooks is executing code, and outputs being able to execute code is one of the key features that enables people to do cool stuff. However, we don’t want notebooks written by not-you to be able to execute code as you on your computer as soon as you open them. For this reason, we have the concept of ‘trusted notebooks’ (introduced in IPython 2), which are notebooks where all output has been produced by you. The main result is that if you get a notebook from someone else with fancy dynamic javascript output, you might see things like:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;code&gt;&amp;lt;Javascript uninteresting repr...&amp;gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;instead of the fancy visualization. Once you either execute the notebook yourself or explicitly trust the notebook from the File menu, you can see the real results.&lt;/p&gt;
&lt;p&gt;When loading output from an untrusted notebook, we take one of three actions:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;the output is &lt;em&gt;unsafe&lt;/em&gt;, and ignored (Javascript)&lt;/li&gt;
&lt;li&gt;the output is &lt;em&gt;potentially unsafe&lt;/em&gt;, and sanitized (HTML)&lt;/li&gt;
&lt;li&gt;the output is &lt;em&gt;safe&lt;/em&gt;, and displayed regardless of trust&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;It’s that third option of “safe” outputs where things went a bit awry. Safe outputs should be outputs that cannot run code in the browser. This includes plain-text output, which we reliably escape, and raster images, such as pngs and jpegs. So far, so good. It also includes latex, which &lt;em&gt;ought&lt;/em&gt; to be like plain text, in that it’s properly escaped before being put on the page to be rendered by &lt;a href="https://www.mathjax.org"&gt;MathJax&lt;/a&gt;. This is where we went wrong. We were putting latex output on the page with jQuery’s &lt;a href="https://api.jquery.com/append/"&gt;&lt;code&gt;$.append&lt;/code&gt;&lt;/a&gt;, which puts elements on the page verbatim. In this way, if the output that claimed to be latex was actually HTML with script tags and such, it would be able to execute code. The &lt;em&gt;right&lt;/em&gt; thing to do (all along) was to use the safe &lt;a href="https://api.jquery.com/text/"&gt;&lt;code&gt;$.text&lt;/code&gt;&lt;/a&gt;, which escapes HTML entities before putting things on the page.&lt;/p&gt;
&lt;p&gt;So that’s &lt;a href="https://github.com/jupyter/notebook/commit/d7fd3e2803afec591abbb3dc32eeab00fa095207"&gt;the fix&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I’m a bit surprised that we didn’t have bugs caused by inequalities and such in equations being mistakenly interpreted as HTML tags.&lt;/p&gt;
&lt;p&gt;See &lt;a href="http://jupyter-notebook.readthedocs.io/en/latest/security.html"&gt;our security docs&lt;/a&gt; for further details on the security model in Jupyter Notebooks.&lt;/p&gt;
&lt;p&gt;If you find a security issue with the notebook or other Jupyter components, please let us know at &lt;a href="http://blog.jupyter.org/cdn-cgi/l/email-protection"&gt;[email protected]&lt;/a&gt;&lt;/p&gt;
</content><category term="Jupyter Notebook"/><category term="releases"/><category term="security"/></entry></feed>