XSSI Vulnerability in Jupyter Notebook by Project Jupyter
CVE-2019-9644

5.4MEDIUM

Key Information:

Vendor

Jupyter

Status
Vendor
CVE Published:
12 March 2019

What is CVE-2019-9644?

An XSSI vulnerability exists in Jupyter Notebook before version 5.7.6, allowing the inclusion of resources from potentially harmful pages when accessed by users authenticated with a Jupyter server. This vulnerability has been illustrated via Internet Explorer, which can capture error messages containing chunks of invalid JavaScript encountered during execution. Although this specific exploit hasn't been confirmed in other browsers, it raises significant security concerns for users operating Jupyter Notebook in an unsecured environment, emphasizing the importance of updating to mitigate risks associated with this vulnerability.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.