JupyterGHSA-92mr-v722-f48m
Improper Input Validation in Jupyter Notebook
Critical9.8CVE-2015-7337 · Published May 17, 2022 · updated Sep 20, 2024
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.
Affected versions
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-20
- Also known as
- CVE-2015-7337, PYSEC-2015-25, PYSEC-2015-27
- nvd.nist.gov/vuln/detail/CVE-2015-7337
- github.com/ipython/ipython/commit/0a8096adf165e2465550bd5893d7e352544e5967
- github.com/jupyter/notebook/commit/9e63dd89b603dfbe3a7e774d8a962ee0fa30c0b5
- bugzilla.redhat.com/show_bug.cgi?id=1264067
- github.com/advisories/GHSA-92mr-v722-f48m
- github.com/pypa/advisory-database/tree/main/vulns/ipython/PYSEC-2015-25.yaml
- github.com/pypa/advisory-database/tree/main/vulns/notebook/PYSEC-2015-27.yaml
- security.gentoo.org/glsa/201512-02
- lists.fedoraproject.org/pipermail/package-announce/2015-September/167670.html
- seclists.org/oss-sec/2015/q3/558
- seclists.org/oss-sec/2015/q3/634
More Jupyter advisories
All Jupyter| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 162022 | Jupyter server Token bruteforcing | High7.1 | 1.17.1+1 more |
| Jun 162022 | Token bruteforcing | Medium4.3 | 6.4.12 |
| May 242022 | Cross-Site Request Forgery in JupyterHub | Medium4.5 | 1.2.0b1 |
| May 142022 | Improper Neutralization of Input During Web Page Generation in Jupyter Notebook | Medium6.1 | 4.0.5+1 more |
| May 142022 | Improper Neutralization of Input During Web Page Generation in Jupyter Notebook | Medium5.4 | 5.7.6 |
| Apr 52022 | Sensitive Auth & Cookie data stored in Jupyter server logs | High7.5 | 6.4.10 |