Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-75cw-5cgv-g853

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.1
CVSS3: 9.8

Описание

IPython Notebook vulnerable to improper validation of the origin of websocket requests

IPython Notebook 0.12 through 1.x before 1.2.0 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.

Пакеты

Наименование

ipython

pip
Затронутые версииВерсия исправления

>= 0.12, < 1.2.0

1.2.0

EPSS

Процентиль: 84%
0.02089
Низкий

8.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

ubuntu
больше 11 лет назад

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.

nvd
больше 11 лет назад

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.

debian
больше 11 лет назад

IPython Notebook 0.12 through 1.x before 1.2 does not validate the ori ...

EPSS

Процентиль: 84%
0.02089
Низкий

8.1 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-94