CVE-2015-6938Cross-site Scripting in Ipython

Severity
4.3MEDIUMNVD
EPSS
0.9%
top 24.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 21
Latest updateJun 30

Description

Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages6 packages

PyPIjupyter/notebook4.0.04.0.5
NVDipython/notebook3.2.1
NVDjupyter/notebook5 versions+4
PyPIipython/ipython< 3.2.2
Debianipython/ipython< 2.4.1-1+3

Also affects: Fedora 21, 22, 23

Patches

🔴Vulnerability Details

4
OSV
Improper Neutralization of Input During Web Page Generation in Jupyter Notebook2022-05-14
GHSA
Improper Neutralization of Input During Web Page Generation in Jupyter Notebook2022-05-14
OSV
CVE-2015-6938: Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp2015-09-21
CVEList
CVE-2015-6938: Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp2015-09-21

📋Vendor Advisories

1
Debian
CVE-2015-6938: ipython - Cross-site scripting (XSS) vulnerability in the file browser in notebook/noteboo...2015

📄Research Papers

1
arXiv
Threat Assessment in Machine Learning based Systems2022-06-30

💬Community

1
Bugzilla
CVE-2015-6938 ipython: XSS via local folder name2015-09-02
CVE-2015-6938 — Cross-site Scripting in Ipython | cvebase