QID 981325
QID 981325: Python (pip) Security Update for notebook (GHSA-49qr-xh3w-h436)
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHandler and NbconvertPostHandler do not set a Content Security Policy to prevent this.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-49qr-xh3w-h436 for updates pertaining to this vulnerability.
Vendor References
- GHSA-49qr-xh3w-h436 -
github.com/advisories/GHSA-49qr-xh3w-h436
CVEs related to QID 981325
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-49qr-xh3w-h436 | notebook |
|