QID 981325

QID 981325: Python (pip) Security Update for notebook (GHSA-49qr-xh3w-h436)

Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-49qr-xh3w-h436 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981325

    Software Advisories
    Advisory ID Software Component Link
    GHSA-49qr-xh3w-h436 notebook URL Logo github.com/advisories/GHSA-49qr-xh3w-h436