CVE-2019-9644
MEDIUMJupyter Notebook < 5.7.6 - Cross-Site Scripting Inclusion via Error Message Capture
Title source: llmDescription
An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though not reproduced with other browsers. This occurs because Internet Explorer's error messages can include the content of any invalid JavaScript that was encountered.
References (3)
Core 3
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/jupyter/notebook/compare/f3f00df...05aa4b2
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UP5RLEES2JBBNSNLBR65XM6PCD4EMF7D/
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMDPJBVXOVO6LYGAT46VZNHH6JKSCURO/
Scores
CVSS v3
5.4
EPSS
0.0164
EPSS Percentile
73.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (3)
jupyter/notebook
< 5.7.6
pypi/jupyter-notebook
0 - 5.7.6PyPI
pypi/notebook
0 - 5.7.6PyPI
Published
Mar 12, 2019
Tracked Since
Feb 18, 2026