PT-2019-19771 · Project Jupyter+2 · Jupyter Notebook+2
Minrk
·
Published
2019-03-12
·
Updated
2022-09-10
·
CVE-2019-9644
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jupyter Notebook versions prior to 5.7.6
Description
A cross-site inclusion issue allows malicious pages to include resources when visited by authenticated users of a Jupyter server. This can lead to access of resource content, particularly demonstrated with Internet Explorer, where error messages can reveal the content of invalid JavaScript.
Recommendations
For versions prior to 5.7.6, update to version 5.7.6 or later to resolve the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jupyter Notebook
Linuxmint
Ubuntu