Skip to content
IPythonGHSA-7fc2-rm35-2pp7

IPython vulnerable to cross site request forgery (CSRF)

High8.8CVE-2015-5607 · Published May 17, 2022 · updated Sep 27, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
ipython
PyPI
>= 0.12, < 2.4.12.4.1
>= 3.0.0, < 3.2.33.2.3
Details and references

More IPython advisories

All IPython
DateAdvisory
May 172022Improper Neutralization of Input During Web Page Generation in IPython
CVE-2015-4706Medium6.1fixed in 3.2.0
May 142022IPython Notebook vulnerable to improper validation of the origin of websocket requests
CVE-2014-3429High9.8fixed in 1.2.0
May 132022Improper Neutralization of Input During Web Page Generation in IPython
CVE-2015-4707Medium6.1fixed in 3.2.0
Jan 212022Execution with Unnecessary Privileges in ipython
CVE-2022-21699High8.2fixed in 5.11, 7.16.3, 7.31.1, 8.0.1
Feb 102023IPython vulnerable to command injection via set_term_title
CVE-2023-24816Low4.5fixed in 8.10.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.