Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqwc-jm56-wcwj

Опубликовано: 08 нояб. 2019
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Cross-site scripting in Jupyter Notebook

Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

Пакеты

Наименование

notebook

pip
Затронутые версииВерсия исправления

< 5.5.0rc1

5.5.0rc1

EPSS

Процентиль: 58%
0.00368
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 6 лет назад

Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

CVSS3: 5.3
nvd
больше 6 лет назад

Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

CVSS3: 5.3
debian
больше 6 лет назад

Jupyter Notebook before 5.5.0 does not use a CSP header to treat serve ...

EPSS

Процентиль: 58%
0.00368
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-79