CVE-2015-6938
published 2015-09-21CVE-2015-6938: Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.77%
84.7th percentile
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ipython | < ipython 2.4.1-1 (bookworm) | ipython 2.4.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| ipython | ipython | >= 0 < 2.4.1-1 | 2.4.1-1 |
| ipython | ipython | >= 0 < 2.4.1-1 | 2.4.1-1 |
| ipython | ipython | >= 0 < 2.4.1-1 | 2.4.1-1 |
| ipython | ipython | >= 0 < 2.4.1-1 | 2.4.1-1 |
| ipython | ipython | >= 0 < 3.2.2 | 3.2.2 |
| ipython | notebook | <= 3.2.1 | — |
| jupyter | notebook | — | — |
| jupyter | notebook | — | — |
| jupyter | notebook | — | — |
| jupyter | notebook | — | — |
| jupyter | notebook | — | — |
| jupyter | notebook | >= 4.0.0 < 4.0.5 | 4.0.5 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Neutralization of Input During Web Page Generation in Jupyter Notebook
osv·2022-05-14
CVE-2015-6938 [MEDIUM] Improper Neutralization of Input During Web Page Generation in Jupyter Notebook
Improper Neutralization of Input During Web Page Generation in Jupyter Notebook
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.
GHSA
Improper Neutralization of Input During Web Page Generation in Jupyter Notebook
ghsa·2022-05-14
CVE-2015-6938 [MEDIUM] CWE-79 Improper Neutralization of Input During Web Page Generation in Jupyter Notebook
Improper Neutralization of Input During Web Page Generation in Jupyter Notebook
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.
OSV
CVE-2015-6938: Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp
osv·2015-09-21·CVSS 4.3
CVE-2015-6938 [MEDIUM] CVE-2015-6938: Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.
Debian
CVE-2015-6938: ipython - Cross-site scripting (XSS) vulnerability in the file browser in notebook/noteboo...
vendor_debian·2015·CVSS 4.3
CVE-2015-6938 [MEDIUM] CVE-2015-6938: ipython - Cross-site scripting (XSS) vulnerability in the file browser in notebook/noteboo...
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.
Scope: local
bookworm: resolved (fixed in 2.4.1-1)
bullseye: resolved (fixed in 2.4.1-1)
forky: resolved (fixed in 2.4.1-1)
sid: resolved (fixed in 2.4.1-1)
trixie: resolved (fixed in 2.4.1-1)
No detection rules found.
No public exploits indexed.
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
Bugzilla
CVE-2015-6938 ipython: XSS via local folder name
bugzilla·2015-09-02·CVSS 4.3
CVE-2015-6938 [MEDIUM] CVE-2015-6938 ipython: XSS via local folder name
CVE-2015-6938 ipython: XSS via local folder name
A flaw was found in IPython's notebook handling:
Local folder name was used in HTML templates without escaping, allowing XSS in said pages by carefully crafting folder name and URL to access it.
Original report:
http://seclists.org/oss-sec/2015/q3/474
Upstream Patches:
3.x: https://github.com/ipython/ipython/commit/3ab41641cf6fce3860c73d5cf4645aa12e1e5892
4.0.x: https://github.com/jupyter/notebook/commit/dd9876381f0ef09873d8c5f6f2063269172331e3
4.x: https://github.com/jupyter/notebook/commit/35f32dd2da804d108a3a3585b69ec3295b2677ed
Discussion:
Created ipython tracking bugs for this issue:
Affects: fedora-all [bug 1259406]
Affects: epel-all [bug 1259407]
---
ipython-2.4.1-8.fc22 has been pushed to the Fedora 22 stable repository. I
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/166460.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/166471.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167670.htmlhttp://lists.opensuse.org/opensuse-updates/2015-10/msg00016.htmlhttp://seclists.org/oss-sec/2015/q3/474http://seclists.org/oss-sec/2015/q3/544https://bugzilla.redhat.com/show_bug.cgi?id=1259405https://github.com/ipython/ipython/commit/3ab41641cf6fce3860c73d5cf4645aa12e1e5892https://github.com/jupyter/notebook/commit/35f32dd2da804d108a3a3585b69ec3295b2677edhttps://github.com/jupyter/notebook/commit/dd9876381f0ef09873d8c5f6f2063269172331e3http://lists.fedoraproject.org/pipermail/package-announce/2015-September/166460.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/166471.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-September/167670.htmlhttp://lists.opensuse.org/opensuse-updates/2015-10/msg00016.htmlhttp://seclists.org/oss-sec/2015/q3/474http://seclists.org/oss-sec/2015/q3/544https://bugzilla.redhat.com/show_bug.cgi?id=1259405https://github.com/ipython/ipython/commit/3ab41641cf6fce3860c73d5cf4645aa12e1e5892https://github.com/jupyter/notebook/commit/35f32dd2da804d108a3a3585b69ec3295b2677edhttps://github.com/jupyter/notebook/commit/dd9876381f0ef09873d8c5f6f2063269172331e3
2015-09-21
Published