QID 981273
QID 981273: Python (pip) Security Update for notebook (GHSA-6cwv-x26c-w2q4)
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6cwv-x26c-w2q4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-6cwv-x26c-w2q4 -
github.com/advisories/GHSA-6cwv-x26c-w2q4
CVEs related to QID 981273
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6cwv-x26c-w2q4 | notebook |
|