XSSI Vulnerability in Jupyter Notebook by Project Jupyter
CVE-2019-9644
5.4MEDIUM
What is CVE-2019-9644?
An XSSI vulnerability exists in Jupyter Notebook before version 5.7.6, allowing the inclusion of resources from potentially harmful pages when accessed by users authenticated with a Jupyter server. This vulnerability has been illustrated via Internet Explorer, which can capture error messages containing chunks of invalid JavaScript encountered during execution. Although this specific exploit hasn't been confirmed in other browsers, it raises significant security concerns for users operating Jupyter Notebook in an unsecured environment, emphasizing the importance of updating to mitigate risks associated with this vulnerability.
