VulnerabilityModified
CVE-2014-3429
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
MEDIUM 6.8EPSS 4.70%
Does this matter?
Lower severity and a low EPSS score (4.70%). Track it; it rarely justifies an emergency change on its own.
Description
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 4.70% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- opensuse/opensuse · ipython/ipython notebook · mageia/mageia
- Source
- cve@mitre.org
References
- http://advisories.mageia.org/MGASA-2014-0320.htmlThird Party Advisory
- http://lambdaops.com/cross-origin-websocket-hijacking-of-ipythonPress/Media Coverage, Technical Description
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00039.htmlThird Party Advisory
- http://permalink.gmane.org/gmane.comp.python.ipython.devel/13198Broken Link
- http://seclists.org/oss-sec/2014/q3/152Third Party Advisory, VDB Entry
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:160Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=1119890Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94497
- https://github.com/ipython/ipython/pull/4845Issue Tracking, Patch
- http://advisories.mageia.org/MGASA-2014-0320.htmlThird Party Advisory
- http://lambdaops.com/cross-origin-websocket-hijacking-of-ipythonPress/Media Coverage, Technical Description
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00039.htmlThird Party Advisory
- http://permalink.gmane.org/gmane.comp.python.ipython.devel/13198Broken Link
- http://seclists.org/oss-sec/2014/q3/152Third Party Advisory, VDB Entry
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:160Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=1119890Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94497
- https://github.com/ipython/ipython/pull/4845Issue Tracking, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.