Description
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
Published: 2019-10-31
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2432-1 jupyter-notebook security update
EUVD EUVD EUVD-2019-0093 Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
Github GHSA Github GHSA GHSA-jqwc-jm56-wcwj Cross-site scripting in Jupyter Notebook
Ubuntu USN Ubuntu USN USN-5585-1 Jupyter Notebook vulnerabilities
History

No history.

Subscriptions

Jupyter Notebook
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T12:19:27.469Z

Reserved: 2019-10-31T00:00:00.000Z

Link: CVE-2018-21030

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-31T15:15:10.420

Modified: 2024-11-21T04:02:44.097

Link: CVE-2018-21030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses