The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).
                
            Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  Debian DLA | 
                DLA-3442-1 | nbconvert security update | 
  Debian DLA | 
                DLA-3863-1 | nbconvert security update | 
  EUVD | 
                EUVD-2022-0161 | The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer). | 
  Github GHSA | 
                GHSA-9jmq-rx5f-8jwq | nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        History
                    Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-02T21:02:59.728Z
Reserved: 2021-05-12T00:00:00
Link: CVE-2021-32862
No data.
Status : Modified
Published: 2022-08-18T19:15:14.337
Modified: 2024-11-21T06:07:54.300
Link: CVE-2021-32862
No data.
                        OpenCVE Enrichment
                    No data.
 Debian DLA
 EUVD
 Github GHSA