<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for python-jupyterlab</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2022:10075-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2022-08-02T10:20:19Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2022-08-02T10:20:19Z</InitialReleaseDate>
    <CurrentReleaseDate>2022-08-02T10:20:19Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for python-jupyterlab</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for python-jupyterlab fixes the following issues:

Update to 2.2.10:

* Remove `form` tags' `action` attribute during sanitizing, to prevent an
  XSS (CVE-2021-32797) (boo#1196663)
* Header ‘Content-Type’ should not be overwritten
* Do not use token parameters in websocket urls
* Properly handle errors in async browser_check
* Cells can no longer be executed while kernels are terminating or
  restarting. There is a new status for these events on the Kernel Indicator
* Add styling for high memory usage warning in status bar with nbresuse
* Adds support for Python version 3.10
* Support live editing of SVG with updating rendering
* Lazy load codemirror theme stylesheets
* Add feature request template + slight reorg in readme
* Add link to react example in extension-examples repo
* Close correct tab with close tab
* Remove unused css rules
* Simplified multicursor backspace code
* Fix recent breaking changes to normalizepath in filebrowser
* Handle quit_button when launched as an extension
* Add worker-loader
* Fix icon sidebar height for third party extensions
* Scrolls cells into view after deletion
* Support Node.js 10+
* Select search text when focusing the search overlay
* Throttle fetch requests in the setting registry’s data connector
* Avoid redundant checkpoint calls on loading a notebook 
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2022-10075</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZGF2ZZFSQOBN7NRPXC3MMQXPLYLS2IH/</URL>
      <Description>E-Mail link for openSUSE-SU-2022:10075-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196663</URL>
      <Description>SUSE Bug 1196663</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-32797/</URL>
      <Description>SUSE CVE CVE-2021-32797 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="SUSE Package Hub 15 SP4">
      <Branch Type="Product Name" Name="SUSE Package Hub 15 SP4">
        <FullProductName ProductID="SUSE Package Hub 15 SP4">SUSE Package Hub 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.4">
      <Branch Type="Product Name" Name="openSUSE Leap 15.4">
        <FullProductName ProductID="openSUSE Leap 15.4" CPE="cpe:/o:opensuse:leap:15.4">openSUSE Leap 15.4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="jupyter-jupyterlab-2.2.10-bp154.2.3.1">
      <FullProductName ProductID="jupyter-jupyterlab-2.2.10-bp154.2.3.1">jupyter-jupyterlab-2.2.10-bp154.2.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-jupyterlab-2.2.10-bp154.2.3.1">
      <FullProductName ProductID="python3-jupyterlab-2.2.10-bp154.2.3.1">python3-jupyterlab-2.2.10-bp154.2.3.1</FullProductName>
    </Branch>
    <Relationship ProductReference="jupyter-jupyterlab-2.2.10-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:jupyter-jupyterlab-2.2.10-bp154.2.3.1">jupyter-jupyterlab-2.2.10-bp154.2.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-jupyterlab-2.2.10-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:python3-jupyterlab-2.2.10-bp154.2.3.1">python3-jupyterlab-2.2.10-bp154.2.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="jupyter-jupyterlab-2.2.10-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:jupyter-jupyterlab-2.2.10-bp154.2.3.1">jupyter-jupyterlab-2.2.10-bp154.2.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-jupyterlab-2.2.10-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:python3-jupyterlab-2.2.10-bp154.2.3.1">python3-jupyterlab-2.2.10-bp154.2.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html `&lt;form&gt;`. Using this it is possible to trigger the form validation outside of the form itself. This is a remote code execution, but requires user action to open a notebook.</Note>
    </Notes>
    <CVE>CVE-2021-32797</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 15 SP4:jupyter-jupyterlab-2.2.10-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:python3-jupyterlab-2.2.10-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:jupyter-jupyterlab-2.2.10-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:python3-jupyterlab-2.2.10-bp154.2.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>9.6</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/VZGF2ZZFSQOBN7NRPXC3MMQXPLYLS2IH/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-32797.html</URL>
        <Description>CVE-2021-32797</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196663</URL>
        <Description>SUSE Bug 1196663</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
