CVE Vulnerabilities

CVE-2018-8768

Published: Mar 18, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is fixed by jQuery after sanitization, making it dangerous.

Affected Software

Name Vendor Start Version End Version
Notebook Jupyter * 5.4.1 (excluding)
Ipython Ubuntu esm-apps/xenial *
Ipython Ubuntu trusty *
Ipython Ubuntu upstream *
Ipython Ubuntu xenial *
Jupyter-notebook Ubuntu artful *
Jupyter-notebook Ubuntu cosmic *
Jupyter-notebook Ubuntu upstream *

References