CVE-2025-32428

Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant to rely on UNIX sockets readable only by the current user since version 3.0.0, but when used with TigerVNC, the VNC server started by jupyter-remote-desktop-proxy were still accessible via the network. This vulnerability does not affect users having TurboVNC as the vncserver executable. This issue is fixed in 3.0.1.
CVSS

No CVSS.

Configurations

No configuration.

History

15 Apr 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 00:15

Updated : 2025-04-15 00:15


NVD link : CVE-2025-32428

Mitre link : CVE-2025-32428


JSON object : View

Products Affected

No product.

CWE
CWE-668

Exposure of Resource to Wrong Sphere