---
title: "CVE-2022-29238\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2022-29238?format=md
keywords: index, follow
---

# CVE-2022-29238

Publication date 14 June 2022

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**4.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2022-29238?format=md#impact-score)

Toggle side navigation

## Description

Jupyter Notebook is a web-based notebook environment for interactive
computing. Prior to version 6.4.12, authenticated requests to the notebook
server with `ContentsManager.allow\_hidden = False` only prevented listing
the contents of hidden directories, not accessing individual hidden files
or files in hidden directories (i.e. hidden files were 'hidden' but not
'inaccessible'). This could lead to notebook configurations allowing
authenticated access to files that may reasonably be expected to be
disallowed. Because fully authenticated requests are required, this is of
relatively low impact. But if a server's root directory contains sensitive
files whose only protection from the server is being hidden (e.g. `~/.ssh`
while serving $HOME), then any authenticated requests could access files if
their names are guessable. Such contexts also necessarily have full access
to the server and therefore execution permissions, which also generally
grants access to all the same files. So this does not generally result in
any privilege escalation or increase in information access, only an
additional, unintended means by which the files could be accessed. Version
6.4.12 contains a patch for this issue. There are currently no known
workarounds.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2022-29238?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| jupyter-notebook | 23.10 mantic | Not affected |
| 23.04 lunar | Ignored end of life, was needed |
| 22.10 kinetic | Ignored end of life, was needed |
| 22.04 LTS jammy | Fixed 6.4.8-1ubuntu0.1 |
| 21.10 impish | Ignored end of life |
| 20.04 LTS focal | Fixed 6.0.3-2ubuntu0.1 |
| 18.04 LTS bionic | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2022-29238?format=md#patch-details)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

the allow-hidden feature was added in jupyter-notebook
upstream commit 605eaa72b ("Added a flag to allow access of hidden
files (#2819)") (version 5.3.0rc1), and as such, bionic's 5.2.x based
version is not affected. Thanks to Luís Infante da Câmara for
researching this.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| jupyter-notebook | * Upstream:   [a161ffa](https://github.com/jupyter/notebook/commit/a161ffac6bfff2491fe5c4e9f6111256b8b57f08) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

4.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 4.3 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29238)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-29238)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2022-29238)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2022-29238)

### Related Ubuntu Security Notices (USN)

+ [USN-5585-1](https://usn.ubuntu.com/USN-5585-1)
+ Jupyter Notebook vulnerabilities
+ 30 August 2022

### Other references

* <https://github.com/jupyter/notebook/security/advisories/GHSA-v7vq-3x77-87vg>
* <https://www.cve.org/CVERecord?id=CVE-2022-29238>
