Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-49qr-xh3w-h436

Опубликовано: 21 нояб. 2018
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 6.1

Описание

Jupyter Notebook XSS via untrusted notebooks

Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.

Пакеты

Наименование

notebook

pip
Затронутые версииВерсия исправления

< 5.7.1

5.7.1

EPSS

Процентиль: 53%
0.00307
Низкий

5.1 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 7 лет назад

Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.

CVSS3: 6.1
nvd
около 7 лет назад

Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.

CVSS3: 6.1
debian
около 7 лет назад

Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook bec ...

EPSS

Процентиль: 53%
0.00307
Низкий

5.1 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79