Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-8768

Опубликовано: 18 мар. 2018
Источник: nvd
CVSS3: 7.8
CVSS2: 6.8
EPSS Низкий

Описание

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jupyter:notebook:*:*:*:*:*:*:*:*
Версия до 5.4.1 (исключая)

EPSS

Процентиль: 32%
0.0012
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.

CVSS3: 7.8
debian
почти 8 лет назад

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file c ...

CVSS3: 7.8
github
больше 7 лет назад

Jupyter Notebook file bypasses sanitization, executes JavaScript

EPSS

Процентиль: 32%
0.0012
Низкий

7.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo