QID 982600
QID 982600: Python (pip) Security Update for notebook (GHSA-jqwc-jm56-wcwj)
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jqwc-jm56-wcwj for updates pertaining to this vulnerability.
Vendor References
- GHSA-jqwc-jm56-wcwj -
github.com/advisories/GHSA-jqwc-jm56-wcwj
CVEs related to QID 982600
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jqwc-jm56-wcwj | notebook |
|