id: jupyter-ipython-unauth info: name: Jupyter ipython - Authorization Bypass author: pentest_swissky severity: critical description: Jupyter was able to be accessed without authentication. classification: cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H cvss-score: 10 cwe-id: CWE-288 metadata: max-request: 1 tags: unauth,jupyter,misconfig http: - method: GET path: - "{{BaseURL}}/ipython/tree" matchers-condition: and matchers: - type: status status: - 200 - type: word words: - ipython/static/components - ipython/kernelspecs part: body # digest: 4a0a0047304502205b9f3ecf1c6223b36c4817e9dd8f201e4904cd8b4a970c59669da0f49bd3975b0221008b564b9649c0744310b0a46d85a9627f6aaa8a3a8789944bb5e1de7ec1596158:922c64590222798bb761d5b6d8e72950