CVE-2025-32428

Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the network. This vulnerability does not affect users having TurboVNC as the vncserver executable. This issue is fixed in 3.0.1.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2025, 18:39

Type Values Removed Values Added
Summary
  • (es) Jupyter Remote Desktop Proxy permite ejecutar un escritorio Linux en un JupyterHub. Desde la versión 3.0.0, jupyter-remote-desktop-proxy estaba diseñado para depender de sockets UNIX legibles únicamente por el usuario actual, pero al usarlo con TigerVNC, el servidor VNC iniciado por jupyter-remote-desktop-proxy seguía siendo accesible a través de la red. Esta vulnerabilidad no afecta a los usuarios que tienen TurboVNC como ejecutable de vncserver. Este problema se solucionó en la versión 3.0.1.

15 Apr 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 00:15

Updated : 2025-04-15 18:39


NVD link : CVE-2025-32428

Mitre link : CVE-2025-32428

CVE.ORG link : CVE-2025-32428


JSON object : View

Products Affected

No product.

CWE
CWE-668

Exposure of Resource to Wrong Sphere