Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-32798

Опубликовано: 09 авг. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 6.8
CVSS3: 10

Описание

The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

6.4.8-1
esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

not-affected

6.4.8-1
esm-apps/noble

not-affected

6.4.8-1
esm-infra-legacy/trusty

DNE

focal

ignored

end of standard support, was needs-triage
hirsute

ignored

end of life
impish

ignored

end of life

Показывать по

6.8 Medium

CVSS2

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
nvd
больше 4 лет назад

The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.

CVSS3: 10
debian
больше 4 лет назад

The Jupyter notebook is a web-based notebook environment for interacti ...

CVSS3: 10
github
больше 4 лет назад

Special Element Injection in notebook

CVSS3: 9.6
fstec
больше 4 лет назад

Уязвимость компонента Caja среды создания документов блокнота Jupyter Notebook, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

suse-cvrf
больше 1 года назад

Security update for python-notebook

6.8 Medium

CVSS2

10 Critical

CVSS3