Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hhx8-cr55-qcxx

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 5.1
CVSS3: 5.4

Описание

Improper Neutralization of Input During Web Page Generation in Jupyter Notebook

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though not reproduced with other browsers. This occurs because Internet Explorer's error messages can include the content of any invalid JavaScript that was encountered.

Пакеты

Наименование

jupyter-notebook

pip
Затронутые версииВерсия исправления

<= 5.7.5

5.7.6

Наименование

notebook

pip
Затронутые версииВерсия исправления

< 5.7.6

5.7.6

EPSS

Процентиль: 77%
0.01017
Низкий

5.1 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
почти 7 лет назад

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though not reproduced with other browsers. This occurs because Internet Explorer's error messages can include the content of any invalid JavaScript that was encountered.

CVSS3: 5.4
nvd
почти 7 лет назад

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though not reproduced with other browsers. This occurs because Internet Explorer's error messages can include the content of any invalid JavaScript that was encountered.

CVSS3: 5.4
debian
почти 7 лет назад

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook befor ...

EPSS

Процентиль: 77%
0.01017
Низкий

5.1 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-79