IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ipython | Jul 30, 2024 | Aug 7, 2014 |
| Suse | — | Upgrade python-pyzmqUpgrade python-pyzmq-develUpgrade IPythonUpgrade IPython-docUpgrade python-pyzmq-debuginfoUpgrade python-pyzmq-debugsource | Dec 18, 2015 | Aug 7, 2014 |
| Ubuntu | — | Upgrade ipython | Nov 19, 2024 | Aug 7, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub