Project Jupyter · Ipython Notebook · CVE-2014-3429
**Name of the Vulnerable Software and Affected Versions**
IPython Notebook versions 0.12 through 1.x before 1.2.0
**Description**
The issue allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page, due to the lack of validation of the origin of websocket requests.
**Recommendations**
For IPython Notebook versions 0.12 through 1.x before 1.2.0, update to version 1.2.0 or later to resolve the issue.