Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

Project Subscriptions

Vendors Products
Jupyter Subscribe
Notebook Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2432-1 jupyter-notebook security update
EUVD EUVD EUVD-2019-0093 Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
Github GHSA Github GHSA GHSA-jqwc-jm56-wcwj Cross-site scripting in Jupyter Notebook
Ubuntu USN Ubuntu USN USN-5585-1 Jupyter Notebook vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T12:19:27.469Z

Reserved: 2019-10-31T00:00:00

Link: CVE-2018-21030

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-10-31T15:15:10.420

Modified: 2024-11-21T04:02:44.097

Link: CVE-2018-21030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses