cbcvebase.
CVE-2021-32798
published 2021-08-09

CVE-2021-32798: The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter…

PriorityP350critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
2.11%
79.7th percentile
The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted notebook can execute code on load. Jupyter Notebook uses a deprecated version of Google Caja to sanitize user inputs. A public Caja bypass can be used to trigger an XSS when a victim opens a malicious ipynb document in Jupyter Notebook. The XSS allows an attacker to execute arbitrary code on the victim computer using Jupyter APIs.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianjupyter-notebook< jupyter-notebook 6.4.3-1 (bookworm)jupyter-notebook 6.4.3-1 (bookworm)
jupyternotebook< 5.7.115.7.11
jupyternotebook
jupyternotebook
jupyternotebook>= 0 < 5.7.115.7.11
jupyternotebook>= 5.7.0 < 5.7.115.7.11
jupyternotebook>= 6.0.0 < 6.4.16.4.1

CVSS provenance

nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
ghsa9.6CRITICAL
osv9.6CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.