<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 17:05:32 +0000</lastBuildDate>
    <item>
      <title>CVE-2024-28188 — jupyter-scheduler's endpoint is missing authentication</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2024-28188</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; jupyter-server jupyter-scheduler, jupyter scheduler&lt;/p&gt;
&lt;p&gt;Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-scheduler` users maybe be exposed, potentially revealing information about projects that a specific user may be working on. This vulnerability has been patched in version(s) 1.1.6, 1.2.1, 1.8.2 and 2.5.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; jupyter-server jupyter-scheduler, jupyter scheduler&lt;/p&gt;
&lt;p&gt;Jupyter Scheduler is collection of extensions for programming jobs to run now or run on a schedule. The list of conda environments of `jupyter-scheduler` users maybe be exposed, potentially revealing information about projects that a specific user may be working on. This vulnerability has been patched in version(s) 1.1.6, 1.2.1, 1.8.2 and 2.5.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2024-28188</guid>
    </item>
    <item>
      <title>GHSA-v9g2-g7j4-4jxc — jupyter-scheduler's endpoint is missing authentication</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-v9g2-g7j4-4jxc</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jupyter-scheduler&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;`jupyter_scheduler` is missing an authentication check in Jupyter Server on an API endpoint (`GET /scheduler/runtime_environments`) which lists the names of the Conda environments on the server. In affected versions, `jupyter_scheduler` allows an unauthenticated user to obtain the list of Conda environment names on the server. This reveals any information that may be present in a Conda environment name.&lt;/p&gt;
&lt;p&gt;This issue does **not** allow an unauthenticated third party to read, modify, or enter the Conda environments present on the server where `jupyter_scheduler` is running. This issue only reveals the list of Conda environment names.&lt;/p&gt;
&lt;p&gt;Impacted versions: `&amp;gt;=1.0.0,&amp;lt;=1.1.5 ; ==1.2.0 ; &amp;gt;=1.3.0,&amp;lt;=1.8.1 ; &amp;gt;=2.0.0,&amp;lt;=2.5.1`&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;* `jupyter-scheduler==1.1.6`
* `jupyter-scheduler==1.2.1`
* `jupyter-scheduler==1.8.2`
* `jupyter-scheduler==2.5.2`&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Server operators who are unable to upgrade can disable the `jupyter-scheduler` extension with:&lt;/p&gt;
&lt;p&gt;```
jupyter server extension disable jupyter-scheduler
```&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.&lt;/p&gt;
&lt;p&gt;[1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: jupyter-scheduler&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;`jupyter_scheduler` is missing an authentication check in Jupyter Server on an API endpoint (`GET /scheduler/runtime_environments`) which lists the names of the Conda environments on the server. In affected versions, `jupyter_scheduler` allows an unauthenticated user to obtain the list of Conda environment names on the server. This reveals any information that may be present in a Conda environment name.&lt;/p&gt;
&lt;p&gt;This issue does **not** allow an unauthenticated third party to read, modify, or enter the Conda environments present on the server where `jupyter_scheduler` is running. This issue only reveals the list of Conda environment names.&lt;/p&gt;
&lt;p&gt;Impacted versions: `&amp;gt;=1.0.0,&amp;lt;=1.1.5 ; ==1.2.0 ; &amp;gt;=1.3.0,&amp;lt;=1.8.1 ; &amp;gt;=2.0.0,&amp;lt;=2.5.1`&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;* `jupyter-scheduler==1.1.6`
* `jupyter-scheduler==1.2.1`
* `jupyter-scheduler==1.8.2`
* `jupyter-scheduler==2.5.2`&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;Server operators who are unable to upgrade can disable the `jupyter-scheduler` extension with:&lt;/p&gt;
&lt;p&gt;```
jupyter server extension disable jupyter-scheduler
```&lt;/p&gt;
&lt;p&gt;### References&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.&lt;/p&gt;
&lt;p&gt;[1] Vulnerability reporting page: https://aws.amazon.com/security/vulnerability-reporting&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-v9g2-g7j4-4jxc</guid>
    </item>
  </channel>
</rss>
