CVE-2015-7337
published 2015-09-29CVE-2015-7337: The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
1.69%
74.5th percentile
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ipython | — | — |
| ipython | ipython | >= 0 < 3.2.2 | 3.2.2 |
| ipython | ipython | >= 0 < 0a8096adf165e2465550bd5893d7e352544e5967 | 0a8096adf165e2465550bd5893d7e352544e5967 |
| ipython | notebook | <= 3.2.1 | — |
| jupyter | notebook | — | — |
| jupyter | notebook | — | — |
| jupyter | notebook | — | — |
| jupyter | notebook | — | — |
| jupyter | notebook | — | — |
| jupyter | notebook | >= 4.0.0 < 4.0.5 | 4.0.5 |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian6.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Input Validation in Jupyter Notebook
osv·2022-05-17
CVE-2015-7337 [CRITICAL] Improper Input Validation in Jupyter Notebook
Improper Input Validation in Jupyter Notebook
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.
GHSA
Improper Input Validation in Jupyter Notebook
ghsa·2022-05-17
CVE-2015-7337 [CRITICAL] CWE-20 Improper Input Validation in Jupyter Notebook
Improper Input Validation in Jupyter Notebook
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.
OSV
CVE-2015-7337: The editor in IPython Notebook before 3
osv·2015-09-29
CVE-2015-7337 CVE-2015-7337: The editor in IPython Notebook before 3
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.
Debian
CVE-2015-7337: ipython - The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4....
vendor_debian·2015·CVSS 6.8
CVE-2015-7337 [MEDIUM] CVE-2015-7337: ipython - The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4....
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
Bugzilla
CVE-2015-7337 ipython: Maliciously crafted files can be executed due to wrong file type determination
bugzilla·2015-09-17·CVSS 6.8
CVE-2015-7337 [MEDIUM] CVE-2015-7337 ipython: Maliciously crafted files can be executed due to wrong file type determination
CVE-2015-7337 ipython: Maliciously crafted files can be executed due to wrong file type determination
A vulnerability in IPython allowing maliciously forged file to be opened for editing that could execute javascript code, specifically by being redirected to /files/ due to the mistakenly treating the file as plain text. Versions >= 3.0 and <= 3.2.1 of IPython are affected.
Upstream patch:
https://github.com/ipython/ipython/commit/0a8096adf165e2465550bd5893d7e352544e5967
CVE request:
http://seclists.org/oss-sec/2015/q3/558
Discussion:
Created ipython tracking bugs for this issue:
Affects: epel-7 [bug 1264068]
---
ipython-3.2.1-3.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167670.htmlhttp://seclists.org/oss-sec/2015/q3/558http://seclists.org/oss-sec/2015/q3/634https://bugzilla.redhat.com/show_bug.cgi?id=1264067https://github.com/ipython/ipython/commit/0a8096adf165e2465550bd5893d7e352544e5967https://github.com/jupyter/notebook/commit/9e63dd89b603dfbe3a7e774d8a962ee0fa30c0b5https://security.gentoo.org/glsa/201512-02http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167670.htmlhttp://seclists.org/oss-sec/2015/q3/558http://seclists.org/oss-sec/2015/q3/634https://bugzilla.redhat.com/show_bug.cgi?id=1264067https://github.com/ipython/ipython/commit/0a8096adf165e2465550bd5893d7e352544e5967https://github.com/jupyter/notebook/commit/9e63dd89b603dfbe3a7e774d8a962ee0fa30c0b5https://security.gentoo.org/glsa/201512-02
2015-09-29
Published