[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*


oval:org.secpod.oval:def:603771
jupyter-notebook is installed

oval:org.secpod.oval:def:707688
jupyter-notebook: Jupyter interactive notebook Several security issues were fixed in Jupyter Notebook.

oval:org.secpod.oval:def:2000569
In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is "fixed" by jQuery after sanitization, making it dangerous.

oval:org.secpod.oval:def:2001418
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.

oval:org.secpod.oval:def:2001255
Jupyter Notebook before 5.7.1 allows XSS via an untrusted notebook because nbconvert responses are considered to have the same origin as the notebook server. In other words, nbconvert endpoints can execute JavaScript with access to the server API. In notebook/nbconvert/handlers.py, NbconvertFileHand ...

CVE    11
CVE-2021-32798
CVE-2020-26215
CVE-2018-19352
CVE-2018-19351
...
*CPE
cpe:/a:jupyter:notebook

© SecPod Technologies