JupyterGHSA-jqwc-jm56-wcwj
Cross-site scripting in Jupyter Notebook
Medium5.3CVE-2018-21030 · Published Nov 8, 2019 · updated Oct 7, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| notebook PyPI | < 5.5.0rc1 | 5.5.0rc1 |
Details and references
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2018-21030, PYSEC-2019-157
- nvd.nist.gov/vuln/detail/CVE-2018-21030
- github.com/jupyter/notebook/pull/3341
- github.com/jupyter/notebook/commit/e321c80776542b8d6f3411af16f9e21e51e27687
- github.com/advisories/GHSA-jqwc-jm56-wcwj
- github.com/jupyter/notebook
- github.com/jupyter/notebook/releases/tag/5.5.0
- github.com/pypa/advisory-database/tree/main/vulns/notebook/PYSEC-2019-157.yaml
- lists.debian.org/debian-lts-announce/2020/11/msg00033.html
More Jupyter advisories
All Jupyter| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 92019 | Jupyter Notebook open redirect vulnerability CVE-2019-10856Medium6.1fixed in 5.7.8 | Medium6.1 | 5.7.8 |
| Apr 22019 | Open Redirect vulnerability in jupyterhub and notebook CVE-2019-10255Medium6.1fixed in 0.9.6, 5.7.8 | Medium6.1 | 0.9.6, 5.7.8 |
| Nov 212018 | Jupyter Notebook XSS via directory name CVE-2018-19352Medium6.1fixed in 5.7.2 | Medium6.1 | 5.7.2 |
| Nov 212018 | Jupyter Notebook XSS via untrusted notebooks CVE-2018-19351Medium6.1fixed in 5.7.1 | Medium6.1 | 5.7.1 |
| Nov 182020 | Open redirect in Jupyter Notebook CVE-2020-26215Low4.4fixed in 6.1.5 | Low4.4 | 6.1.5 |
| Nov 242020 | Open redirect in Jupyter Server CVE-2020-26232Medium4.1fixed in 1.0.6 | Medium4.1 | 1.0.6 |