{"id":"CVE-2022-21697","aliases":["GHSA-gcv9-6737-pjqw","PYSEC-2022-16"],"url":"https://o3.security/vulnerability/CVE-2022-21697","summary":"SSRF vulnerability (requires authentication)","details":"### Impact\n\n**What kind of vulnerability is it?**  Server-Side Request Forgery ( SSRF )\n\n**Who is impacted?** Any user deploying Jupyter Server or Notebook with jupyter-proxy-server extension enabled. \n\nA lack of input validation allowed authenticated clients to proxy requests to other hosts, bypassing the `allowed_hosts` check. Because authentication is required, which already grants permissions to make the same requests via kernel or terminal execution, this is considered low to moderate severity.\n\n\n### Patches\n\n_Has the problem been patched? What versions should users upgrade to?_\n\nUpgrade to 3.2.1, or apply the patch https://github.com/jupyterhub/jupyter-server-proxy/compare/v3.2.0...v3.2.1.patch\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Open a topic [on our forum](https://discourse.jupyter.org)\n* Email the Jupyter security team at [security@ipython.org](mailto:security@ipython.org)\n","published":"2022-01-25T13:55:12Z","modified":"2026-08-12T03:51:09.172352065Z","cvss":{"score":6.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"jupyter-server-proxy","fixedVersion":"3.2.1"}],"fix":{"url":"https://github.com/jupyterhub/jupyter-server-proxy/commit/fd31930bacd12188c448c886e0783529436b99eb","label":"jupyterhub/jupyter-server-proxy@fd31930"},"references":[{"type":"WEB","url":"https://github.com/jupyterhub/jupyter-server-proxy/compare/v3.2.0...v3.2.1.patch"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/21xxx/CVE-2022-21697.json"},{"type":"ADVISORY","url":"https://github.com/jupyterhub/jupyter-server-proxy/security/advisories/GHSA-gcv9-6737-pjqw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21697"},{"type":"FIX","url":"https://github.com/jupyterhub/jupyter-server-proxy/commit/fd31930bacd12188c448c886e0783529436b99eb"},{"type":"WEB","url":"https://github.com/jupyterhub/jupyter-server-proxy"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server-proxy/PYSEC-2022-16.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:09.172352065Z"}}