Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-92mr-v722-f48m

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

Improper Input Validation in Jupyter Notebook

The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.

Пакеты

Наименование

notebook

pip
Затронутые версииВерсия исправления

>= 4.0.0, <= 4.0.4

4.0.5

Наименование

ipython

pip
Затронутые версииВерсия исправления

<= 3.2.1

3.2.2

EPSS

Процентиль: 73%
0.00775
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 10 лет назад

The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.

nvd
больше 10 лет назад

The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.

debian
больше 10 лет назад

The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x ...

EPSS

Процентиль: 73%
0.00775
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-20