nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment. This has been resolved in version 0.10.2 and all users are advised to upgrade. No work around exist for users who can not upgrade.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-0141 nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, visiting maliciously crafted links could result in arbitrary code execution in the user environment. This has been resolved in version 0.10.2 and all users are advised to upgrade. No work around exist for users who can not upgrade.
Github GHSA Github GHSA GHSA-mq5p-2mcr-m52j Code injection in nbgitpuller
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-04T01:58:18.218Z

Reserved: 2021-08-16T00:00:00

Link: CVE-2021-39160

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-25T18:15:08.487

Modified: 2024-11-21T06:18:45.240

Link: CVE-2021-39160

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.