CVE Vulnerabilities

CVE-2018-8768

Published: Mar 18, 2018 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is fixed by jQuery after sanitization, making it dangerous.

Affected Software

NameVendorStart VersionEnd Version
NotebookJupyter*5.4.1 (excluding)
IpythonUbuntuesm-apps/xenial*
IpythonUbuntutrusty*
IpythonUbuntuupstream*
IpythonUbuntuxenial*
Jupyter-notebookUbuntuartful*
Jupyter-notebookUbuntucosmic*
Jupyter-notebookUbuntuupstream*

References