CVE-2018-8768
published 2018-03-18CVE-2018-8768: In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically…
PriorityP432high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.10%
62.0th percentile
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ipython | < ipython 5.1.0-2 (bookworm) | ipython 5.1.0-2 (bookworm) |
| debian | jupyter-notebook | < ipython 5.1.0-2 (bookworm) | ipython 5.1.0-2 (bookworm) |
| ipython | ipython | >= 0 < 5.1.0-2 | 5.1.0-2 |
| ipython | ipython | >= 0 < 5.1.0-2 | 5.1.0-2 |
| ipython | ipython | >= 0 < 5.1.0-2 | 5.1.0-2 |
| ipython | ipython | >= 0 < 5.1.0-2 | 5.1.0-2 |
| jupyter | notebook | < 5.4.1 | 5.4.1 |
| jupyter | notebook | >= 0 < 5.4.1 | 5.4.1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
IPython vulnerability
vendor_ubuntu·2021-03-15
CVE-2018-8768 IPython vulnerability
Title: IPython vulnerability
Summary: IPython could be made to run programs as an administrator
if it opened a specially crafted notebook file.
It was discovered that IPython did not properly sanitize certain input. If
a user were tricked into opening a specially crafted notebook file, a
remote attacker could possibly use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-8768: ipython - In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass ...
vendor_debian·2018·CVSS 7.8
CVE-2018-8768 [HIGH] CVE-2018-8768: ipython - In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass ...
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
Scope: local
bookworm: resolved (fixed in 5.1.0-2)
bullseye: resolved (fixed in 5.1.0-2)
forky: resolved (fixed in 5.1.0-2)
sid: resolved (fixed in 5.1.0-2)
trixie: resolved (fixed in 5.1.0-2)
OSV
Jupyter Notebook file bypasses sanitization, executes JavaScript
osv·2018-07-12
CVE-2018-8768 [HIGH] Jupyter Notebook file bypasses sanitization, executes JavaScript
Jupyter Notebook file bypasses sanitization, executes JavaScript
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
GHSA
Jupyter Notebook file bypasses sanitization, executes JavaScript
ghsa·2018-07-12
CVE-2018-8768 [HIGH] Jupyter Notebook file bypasses sanitization, executes JavaScript
Jupyter Notebook file bypasses sanitization, executes JavaScript
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
OSV
CVE-2018-8768: In Jupyter Notebook before 5
osv·2018-03-18·CVSS 7.8
CVE-2018-8768 [HIGH] CVE-2018-8768: In Jupyter Notebook before 5
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
No detection rules found.
No public exploits indexed.
arXiv
Threat Assessment in Machine Learning based Systems
arxiv_fulltext·2022-06-30
Threat Assessment in Machine Learning based Systems
Threat Assessment in Machine Learning based Systems
Lionel Nganyewou Tidjon and Foutse Khomh, Senior Member, IEEE
The authors are with Polytechnique Montréal, Montréal, QC H3C 3A7, Canada.
E-mail: \lionel.tidjon, foutse.khomh\@polymtl.ca
## Abstract
Machine learning is a field of artificial intelligence (AI) that is becoming essential for several critical systems, making it a good target for threat actors. Threat actors exploit different Tactics, Techniques, and Procedures (TTPs) against the confidentiality, integrity, and availability of Machine Learning (ML) systems.
During the ML
cycle, they exploit adversarial TTPs to poison data and fool ML-based systems. In recent years, multiple security practices have been proposed for traditional systems but they are not enough to cope with th
Bugzilla
CVE-2018-8768 python-notebook: Input sanitization bypass allows for execution of JavaScript via crafted notebook file [fedora-all]
bugzilla·2018-03-21·CVSS 7.8
CVE-2018-8768 [HIGH] CVE-2018-8768 python-notebook: Input sanitization bypass allows for execution of JavaScript via crafted notebook file [fedora-all]
CVE-2018-8768 python-notebook: Input sanitization bypass allows for execution of JavaScript via crafted notebook file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-8768 python-notebook: Input sanitization bypass allows for execution of JavaScript via crafted notebook file
bugzilla·2018-03-21·CVSS 7.8
CVE-2018-8768 [HIGH] CVE-2018-8768 python-notebook: Input sanitization bypass allows for execution of JavaScript via crafted notebook file
CVE-2018-8768 python-notebook: Input sanitization bypass allows for execution of JavaScript via crafted notebook file
n Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
External References:
http://www.openwall.com/lists/oss-security/2018/03/15/2
Upstream Patch:
https://github.com/jupyter/notebook/commit/4e79ebb49acac722b37b03f1fe811e67590d3831
Discussion:
Created python-notebook tracking bugs for this issue:
Affects: fedora-all [bug 1558783]
---
This was fixed in Fedora a while ago. Should this be closed?
2018-03-18
Published