QID 981346
QID 981346: Python (pip) Security Update for notebook (GHSA-3p4q-x8f3-p7vq)
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3p4q-x8f3-p7vq for updates pertaining to this vulnerability.
Vendor References
- GHSA-3p4q-x8f3-p7vq -
github.com/advisories/GHSA-3p4q-x8f3-p7vq
CVEs related to QID 981346
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3p4q-x8f3-p7vq | notebook |
|