id: unauth-jupyter-lab info: name: Jupyter Lab - Unauthenticated Access author: j4vaovo severity: critical description: | JupyterLab was able to be accessed without authentication. reference: - https://paper.seebug.org/2058/ classification: cvss-metrics: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H cvss-score: 10 cwe-id: CWE-288 metadata: max-request: 1 shodan-query: http.favicon.hash:450899026 tags: unauth,jupyter,jupyterlab,misconfig http: - method: GET path: - '{{BaseURL}}/lab/api/settings/' matchers-condition: and matchers: - type: word part: body words: - '"id":' - '"settings"' - '"schema":' condition: and - type: word part: header words: - "application/json" - type: status status: - 200 # digest: 4a0a004730450221008eac78d5769d98b1c7889c9a71355617961a155ab4026071958c93abcdb40b2102203fdb2a9a5ebe3aa2408a00186580a0a96544cc7f6552aeaec71edf0c7fbe6a4e:922c64590222798bb761d5b6d8e72950