CVE-2014-3429
Summary
| CVE | CVE-2014-3429 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-07 11:13:34 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ipython | Ipython Notebook | 0.12 | All | All | All |
| Application | Ipython | Ipython Notebook | 0.12.1 | All | All | All |
| Application | Ipython | Ipython Notebook | 0.13 | All | All | All |
| Application | Ipython | Ipython Notebook | 0.13.1 | All | All | All |
| Application | Ipython | Ipython Notebook | 0.13.2 | All | All | All |
| Application | Ipython | Ipython Notebook | 1.0.0 | All | All | All |
| Application | Ipython | Ipython Notebook | 1.1.0 | All | All | All |
| Operating System | Mageia | Mageia | 3.0 | All | All | All |
| Operating System | Mageia | Mageia | 4.0 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.1 | All | All | All |
| Operating System | Opensuse | Opensuse | 13.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mageia Advisory: MGASA-2014-0320 - Updated ipython package fixes security vulnerability | af854a3a-2127-422b-91ae-364da2661108 | advisories.mageia.org | Third Party Advisory |
| One Weird Kernel Trick | af854a3a-2127-422b-91ae-364da2661108 | lambdaops.com | Press/Media Coverage, Technical Description |
| Vulnerability in IPython Notebook ≤ 1.1 | af854a3a-2127-422b-91ae-364da2661108 | permalink.gmane.org | Broken Link |
| oss-sec: IPython Notebook Cross 2014-3429 | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Third Party Advisory, VDB Entry |
| Add Origin Checking. by rgbkrk · Pull Request #4845 · ipython/ipython · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Issue Tracking, Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Bug 1119890 – CVE-2014-3429 ipython: cross-domain websocket hijacking vulnerability | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking |
| openSUSE-SU-2014:1060-1: moderate: update for IPython | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | Third Party Advisory |
| Support / Security / Advisories / / MDVSA-2015:160 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | Broken Link |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.