CVE-2018-21030

MEDIUM

Jupyter Notebook < 5.5.0 - Cross-Site Scripting via SVG File

Title source: llm
STIX 2.1

Description

Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

References (3)

Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/jupyter/notebook/pull/3341
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/jupyter/notebook/releases/tag/5.5.0
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/11/msg00033.html

Scores

CVSS v3 5.3
EPSS 0.0144
EPSS Percentile 69.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-79 CWE-863
Status published
Products (2)
jupyter/notebook < 5.5.0
pypi/notebook 0 - 5.5.0rc1PyPI
Published Oct 31, 2019
Tracked Since Feb 18, 2026