SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-9644

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server.

MEDIUM 5.4EPSS 1.53%

Does this matter?

Lower severity and a low EPSS score (1.53%). Track it; it rarely justifies an emergency change on its own.

Description

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though not reproduced with other browsers. This occurs because Internet Explorer's error messages can include the content of any invalid JavaScript that was encountered.

CVSS 3.0
5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS
1.53% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
jupyter/notebook
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.