CVE-2018-21030
published 2019-10-31CVE-2018-21030: Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be…
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.44%
70.6th percentile
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jupyter-notebook | < jupyter-notebook 5.7.4-1 (bookworm) | jupyter-notebook 5.7.4-1 (bookworm) |
| jupyter | notebook | < 5.5.0 | 5.5.0 |
| jupyter | notebook | >= 0 < 5.5.0rc1 | 5.5.0rc1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Jupyter Notebook vulnerabilities
vendor_ubuntu·2022-08-30·CVSS 6.1
CVE-2022-24758 [MEDIUM] Jupyter Notebook vulnerabilities
Title: Jupyter Notebook vulnerabilities
Summary: Several security issues were fixed in Jupyter Notebook.
It was discovered that Jupyter Notebook incorrectly handled certain notebooks.
An attacker could possibly use this issue of lack of Content Security Policy
in Nbconvert to perform cross-site scripting (XSS) attacks on the notebook
server. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-19351)
It was discovered that Jupyter Notebook incorrectly handled certain SVG
documents. An attacker could possibly use this issue to perform cross-site
scripting (XSS) attacks. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-21030)
It was discovered that Jupyter Notebook incorrectly filtered certain URLs on
the login page. An attacker could possibly use this issue to perform
open-redirect
Debian
CVE-2018-21030: jupyter-notebook - Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as...
vendor_debian·2018·CVSS 5.3
CVE-2018-21030 [MEDIUM] CVE-2018-21030: jupyter-notebook - Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as...
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
Scope: local
bookworm: resolved (fixed in 5.7.4-1)
bullseye: resolved (fixed in 5.7.4-1)
forky: resolved (fixed in 5.7.4-1)
sid: resolved (fixed in 5.7.4-1)
trixie: resolved (fixed in 5.7.4-1)
OSV
jupyter-notebook vulnerabilities
osv·2022-08-30·CVSS 6.1
CVE-2018-19351 [MEDIUM] jupyter-notebook vulnerabilities
jupyter-notebook vulnerabilities
It was discovered that Jupyter Notebook incorrectly handled certain notebooks.
An attacker could possibly use this issue of lack of Content Security Policy
in Nbconvert to perform cross-site scripting (XSS) attacks on the notebook
server. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-19351)
It was discovered that Jupyter Notebook incorrectly handled certain SVG
documents. An attacker could possibly use this issue to perform cross-site
scripting (XSS) attacks. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-21030)
It was discovered that Jupyter Notebook incorrectly filtered certain URLs on
the login page. An attacker could possibly use this issue to perform
open-redirect attack. This issue only affected Ubuntu 18.04 LTS.
(CVE-2019-10255)
It w
OSV
Cross-site scripting in Jupyter Notebook
osv·2019-11-08
CVE-2018-21030 [MEDIUM] Cross-site scripting in Jupyter Notebook
Cross-site scripting in Jupyter Notebook
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
GHSA
Cross-site scripting in Jupyter Notebook
ghsa·2019-11-08
CVE-2018-21030 [MEDIUM] CWE-79 Cross-site scripting in Jupyter Notebook
Cross-site scripting in Jupyter Notebook
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
OSV
CVE-2018-21030: Jupyter Notebook before 5
osv·2019-10-31·CVSS 5.3
CVE-2018-21030 [MEDIUM] CVE-2018-21030: Jupyter Notebook before 5
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
No detection rules found.
No public exploits indexed.
https://github.com/jupyter/notebook/pull/3341https://github.com/jupyter/notebook/releases/tag/5.5.0https://lists.debian.org/debian-lts-announce/2020/11/msg00033.htmlhttps://github.com/jupyter/notebook/pull/3341https://github.com/jupyter/notebook/releases/tag/5.5.0https://lists.debian.org/debian-lts-announce/2020/11/msg00033.html
2019-10-31
Published