Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-19351

Опубликовано: 18 нояб. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.1

Описание

Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.

РелизСтатусПримечание
bionic

released

5.2.2-1ubuntu0.1
cosmic

ignored

end of life
devel

not-affected

6.4.8-2
disco

not-affected

5.7.4-1
eoan

ignored

end of life
esm-apps/bionic

released

5.2.2-1ubuntu0.1
esm-apps/focal

not-affected

6.0.3-2
esm-apps/jammy

not-affected

6.4.8-1
esm-infra-legacy/trusty

DNE

focal

not-affected

6.0.3-2

Показывать по

EPSS

Процентиль: 53%
0.00307
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
около 7 лет назад

Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.

CVSS3: 6.1
debian
около 7 лет назад

Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook bec ...

CVSS3: 6.1
github
около 7 лет назад

Jupyter Notebook XSS via untrusted notebooks

EPSS

Процентиль: 53%
0.00307
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3