security

Jupyter Security Sprint March 31st

This is a critical moment for open source software. AI enables new contributors in new ways, but maintainers are also faced with an unprecedented volume of contributions and security reports. This speed also puts pressure on maintainers and the processes that keep projects secure and reliable.

· Joe Lucas

Trusted CI Cybersecurity Engagement with Jupyter

Trusted CI is the US National Science Foundation Cybersecurity Center of Excellence, staffed by cybersecurity experts who have spent decades working with science and engineering communities and who have established track records in terms of usable, high-quality solutions suited to the needs of…

· Rollin Thomas

Jupyter’s role in #ChaosDB

On August 26 it was revealed that a misconfiguration in Microsoft’s internal deployment of CosmosDB using Jupyter would allow attackers to access all customer data. Fortunately, they report no evidence that customer data was compromised.

· Matthias Bussonnier

Jupyter notebook XSSI security fix

We have just released Jupyter notebook 5.7.6 with a security fix for a cross-site inclusion (XSSI) vulnerability, where content from a Jupyter server could be included in another page if the visitor is logged in to the Jupyter server and the author of the page knows the URL of the server and the…

· Min RK

Jupyter Notebook

Jupyter Notebook security fixes

Two security issues have been found and fixed this week, where untrusted javascript could be executed if malicious files could be delivered to the users system and the user takes specific actions with those malicious files.

· Min RK

Jupyter Notebook

Security fix for Jupyter Notebook

We have just released Jupyter Notebook 5.6.0. This release fixes a vulnerability that could allow a maliciously crafted notebook to execute JavaScript when it is opened, bypassing the trusted-notebook mechanism.

· Min RK

Jupyter Notebook