Vulnerability Description
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jupyter | Notebook | < 5.7.2 |
Related Weaknesses (CWE)
References
- https://github.com/jupyter/notebook/blob/master/docs/source/changelog.rstRelease Notes
- https://github.com/jupyter/notebook/commit/288b73e1edbf527740e273fcc69b889460871PatchThird Party Advisory
- https://pypi.org/project/notebook/#historyRelease Notes
- https://github.com/jupyter/notebook/blob/master/docs/source/changelog.rstRelease Notes
- https://github.com/jupyter/notebook/commit/288b73e1edbf527740e273fcc69b889460871PatchThird Party Advisory
- https://pypi.org/project/notebook/#historyRelease Notes
FAQ
What is CVE-2018-19352?
CVE-2018-19352 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
How severe is CVE-2018-19352?
CVE-2018-19352 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19352?
Check the references section above for vendor advisories and patch information. Affected products include: Jupyter Notebook.