CVE-2015-4707Cross-site Scripting in Ipython

Severity
6.1MEDIUMNVD
EPSS
0.9%
top 24.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 20
Latest updateMay 13

Description

Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving JSON error messages and the /api/notebooks path.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

NVDipython/ipython< 3.2.0
PyPIipython/ipython< 3.2.0
Debianipython/ipython< 2.4.1-1+3

Patches

🔴Vulnerability Details

4
OSV
Improper Neutralization of Input During Web Page Generation in IPython2022-05-13
GHSA
Improper Neutralization of Input During Web Page Generation in IPython2022-05-13
CVEList
CVE-2015-4707: Cross-site scripting (XSS) vulnerability in IPython before 32017-09-20
OSV
CVE-2015-4707: Cross-site scripting (XSS) vulnerability in IPython before 32017-09-20

📋Vendor Advisories

1
Debian
CVE-2015-4707: ipython - Cross-site scripting (XSS) vulnerability in IPython before 3.2 allows remote att...2015

💬Community

1
Bugzilla
CVE-2015-4706 CVE-2015-4707 ipython: IPython 3.2 contains important security fixes2015-06-25
CVE-2015-4707 — Cross-site Scripting in Ipython | cvebase