CVE-2021-32862
published 2022-08-18CVE-2021-32862: The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version…
PriorityP424medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.11%
62.7th percentile
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | nbconvert | < nbconvert 6.5.1-1 (bookworm) | nbconvert 6.5.1-1 (bookworm) |
| jupyter | nbconvert | <= 6.2.0 | — |
| jupyter | nbconvert | >= 0 < 5.6.1-3+deb11u1 | 5.6.1-3+deb11u1 |
| jupyter | nbconvert | >= 0 < 6.5.1-1 | 6.5.1-1 |
| jupyter | nbconvert | >= 0 < 6.5.1-1 | 6.5.1-1 |
| jupyter | nbconvert | >= 0 < 6.5.1-1 | 6.5.1-1 |
| jupyter | nbconvert | >= 0 < 6.5.1 | 6.5.1 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
osv5.4MEDIUM
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2021-32862: The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert
osv·2022-08-18·CVSS 5.4
CVE-2021-32862 [MEDIUM] CVE-2021-32862: The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).
OSV
nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
osv·2022-08-10
CVE-2021-32862 [MEDIUM] nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Most of the fixes will be in this repo, though, so having it here gives us the private fork to work on patches
Below is currently a duplicate of the original report:
----
Received on [email protected] unedited, I'm not sure if we want to make it separate advisories.
Pasted raw for now, feel free to edit or make separate advisories if you have the rights to.
I think the most important is to switch back from nbviewer.jupyter.org -> nbviewer.org at the cloudflare level I guess ? There might be fastly involved as well.
---
### Impact
_What kind of vulnerability is it? Who is impacted?_
### Patches
_Has the problem been patched? What versions should users upgrade to?_
### Workarounds
_Is there a way for use
GHSA
nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
ghsa·2022-08-10
CVE-2021-32862 [MEDIUM] CWE-79 nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths
Most of the fixes will be in this repo, though, so having it here gives us the private fork to work on patches
Below is currently a duplicate of the original report:
----
Received on [email protected] unedited, I'm not sure if we want to make it separate advisories.
Pasted raw for now, feel free to edit or make separate advisories if you have the rights to.
I think the most important is to switch back from nbviewer.jupyter.org -> nbviewer.org at the cloudflare level I guess ? There might be fastly involved as well.
---
### Impact
_What kind of vulnerability is it? Who is impacted?_
### Patches
_Has the problem been patched? What versions should users upgrade to?_
### Workarounds
_Is there a way for use
Debian
CVE-2021-32862: nbconvert - The GitHub Security Lab discovered sixteen ways to exploit a cross-site scriptin...
vendor_debian·2021·CVSS 7.5
CVE-2021-32862 [HIGH] CVE-2021-32862: nbconvert - The GitHub Security Lab discovered sixteen ways to exploit a cross-site scriptin...
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).
Scope: local
bookworm: resolved (fixed in 6.5.1-1)
bullseye: resolved (fixed in 5.6.1-3+deb11u1)
forky: resolved (fixed in 6.5.1-1)
sid: resolved (fixed in 6.5.1-1)
trixie: resolved (fixed in 6.5.1-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/jupyter/nbconvert/security/advisories/GHSA-9jmq-rx5f-8jwqhttps://github.com/jupyter/nbviewer/security/advisories/GHSA-h274-fcvj-h2wmhttps://lists.debian.org/debian-lts-announce/2023/06/msg00003.htmlhttps://github.com/jupyter/nbconvert/security/advisories/GHSA-9jmq-rx5f-8jwqhttps://github.com/jupyter/nbviewer/security/advisories/GHSA-h274-fcvj-h2wmhttps://lists.debian.org/debian-lts-announce/2023/06/msg00003.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00004.html
2022-08-18
Published