IBM Support

Security Bulletin: Jupyter vulnerabilities affect IBM Spectrum Conductor 2.3 and IBM Spectrum Conductor with Spark 2.2.1

Created by Steve Haertel on
Published URL:
https://www.ibm.com/support/pages/node/885702
885702

Security Bulletin


Summary

There are multiple vulnerabilities in the Jupyter notebook used by IBM Spectrum Conductor with Spark 2.2.1 and IBM Spectrum Conductor 2.3.0. IBM Spectrum Conductor has addressed the applicable CVEs.

Vulnerability Details

CVE-ID: CVE-2019-9644
Description: Jupyter Notebook could allow a remote attacker to obtain sensitive information, caused by a cross-site inclusion flaw. By persuading a victim to visit a specially-crafted Web site, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base Score: 6.5
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/158122 for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)

CVE-ID: CVE-2019-10255
Description: Jupyter Notebook and JupyterHub could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially-crafted URL to redirect a victim to arbitrary Web sites.
CVSS Base Score: 7.4
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/160618 for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N)

CVE-ID: CVE-2019-10856
Description: Jupyter Notebook and JupyterHub could allow a remote attacker to conduct phishing attacks, caused by an open redirect vulnerability. An attacker could exploit this vulnerability using a specially-crafted URL to redirect a victim to arbitrary Web sites.
CVSS Base Score: 7.4
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/160049 for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N)

Affected Products and Versions

IBM Spectrum Conductor 2.3.0
IBM Spectrum Conductor with Spark 2.2.1

Remediation/Fixes

Download the interim fixes that correspond to your product version from IBM Fix Central, then follow the steps in the accompanying readme to apply the interim fix on Linux x86_64 hosts in your cluster:

IBM Spectrum Conductor 2.3.0 sc-2.3-build521530
IBM Spectrum Conductor 2.2.1 cws-2.2.1-build521531

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

May 30, 2019 : original version created

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Document Location

Worldwide

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SS4H63","label":"IBM Spectrum Conductor"},"Component":"Jupyter","Platform":[{"code":"PF016","label":"Linux"}],"Version":"2.3.0;2.2.1","Edition":"","Line of Business":{"code":"LOB10","label":"Data and AI"}}]

Document Information

Modified date:
03 July 2019

UID

ibm10885702