Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-9644

Опубликовано: 12 мар. 2019
Источник: nvd
CVSS3: 5.4
CVSS2: 4.3
EPSS Низкий

Описание

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though not reproduced with other browsers. This occurs because Internet Explorer's error messages can include the content of any invalid JavaScript that was encountered.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jupyter:notebook:*:*:*:*:*:*:*:*
Версия до 5.7.6 (исключая)

EPSS

Процентиль: 77%
0.01017
Низкий

5.4 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
почти 7 лет назад

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though not reproduced with other browsers. This occurs because Internet Explorer's error messages can include the content of any invalid JavaScript that was encountered.

CVSS3: 5.4
debian
почти 7 лет назад

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook befor ...

CVSS3: 5.4
github
больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Jupyter Notebook

EPSS

Процентиль: 77%
0.01017
Низкий

5.4 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79