Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2024-39700

9.9 · CRITICAL
Published Jul 16, 2024 jupyter CWE-94 EPSS 1.02% (61th pctl)

Overview

CVE-2024-39700 is a critical-severity vulnerability affecting jupyter jupyterlab. It was published on July 16, 2024 and has a CVSS 3.1 base score of 9.9 (CRITICAL).

This vulnerability has a CVSS 3.1 base score of 9.9, rated CRITICAL. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

Technical Description

JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged to upgrade the template to the latest version. Users who made changes to `update-integration-tests.yml`, accept overwriting of this file and re-apply your changes later. Users may wish to temporarily disable GitHub Actions while working on the upgrade. We recommend rebasing all open pull requests from untrusted users as actions may run using the version from the `main` branch at the time when the pull request was created. Users who are upgrading from template version prior to 4.3.0 may wish to leave out proposed changes to the release workflow for now as it requires additional configuration.

Remediation

Check the references section for vendor advisories and patches from jupyter. Update jupyterlab to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
jupyter jupyterlab >= 0, < 4.3.0 Affected

Frequently Asked Questions

What is CVE-2024-39700?

CVE-2024-39700 is a critical-severity vulnerability affecting jupyter jupyterlab. It was published on July 16, 2024 and has a CVSS 3.1 base score of 9.9 (CRITICAL).

How severe is CVE-2024-39700?

This vulnerability has a CVSS 3.1 base score of 9.9, rated CRITICAL. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2024-39700?

Check the references section for vendor advisories and patches from jupyter. Update jupyterlab to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2024-39700?

CyberStrike's AI-powered security agents can automatically detect CVE-2024-39700 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.