Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4vwq-x64q-j4cj

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.3
CVSS3: 6.1

Описание

Improper Neutralization of Input During Web Page Generation in Jupyter Notebook

Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.

Пакеты

Наименование

notebook

pip
Затронутые версииВерсия исправления

>= 4.0.0, <= 4.0.4

4.0.5

Наименование

ipython

pip
Затронутые версииВерсия исправления

<= 3.2.1

3.2.2

EPSS

Процентиль: 75%
0.00861
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

ubuntu
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.

nvd
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.

debian
больше 10 лет назад

Cross-site scripting (XSS) vulnerability in the file browser in notebo ...

EPSS

Процентиль: 75%
0.00861
Низкий

5.3 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-79