IPythonGHSA-75cw-5cgv-g853
IPython Notebook vulnerable to improper validation of the origin of websocket requests
High9.8CVE-2014-3429 · Published May 14, 2022 · updated Sep 23, 2024
IPython Notebook 0.12 through 1.x before 1.2.0 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ipython PyPI | >= 0.12, < 1.2.0 | 1.2.0 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2014-3429, PYSEC-2014-21
- nvd.nist.gov/vuln/detail/CVE-2014-3429
- github.com/ipython/ipython/pull/4845
- github.com/ipython/ipython/commit/e5b669ce4750d628dba383fd637dbde918ea15f5
- github.com/mattvonrocketstein/ipython/commit/dd4135db9f42d196a46553310a8e63ff5658671d
- bugzilla.redhat.com/show_bug.cgi?id=1119890
- exchange.xforce.ibmcloud.com/vulnerabilities/94497
- github.com/ipython/ipython
- github.com/pypa/advisory-database/tree/main/vulns/ipython/PYSEC-2014-21.yaml
- advisories.mageia.org/MGASA-2014-0320.html
- lambdaops.com/cross-origin-websocket-hijacking-of-ipython
- lists.opensuse.org/opensuse-updates/2014-08/msg00039.html
- permalink.gmane.org/gmane.comp.python.ipython.devel/13198
- seclists.org/oss-sec/2014/q3/152
More IPython advisories
All IPython| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 102023 | IPython vulnerable to command injection via set_term_title | Low4.5 | 8.10.0 |
| May 172022 | Improper Neutralization of Input During Web Page Generation in IPython | Medium6.1 | 3.2.0 |
| May 172022 | IPython vulnerable to cross site request forgery (CSRF) | High8.8 | 2.4.1+1 more |
| May 132022 | Improper Neutralization of Input During Web Page Generation in IPython | Medium6.1 | 3.2.0 |
| Jan 212022 | Execution with Unnecessary Privileges in ipython | High8.2 | 5.11+3 more |