CVE-2018-21030 PUBLISHED

Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

EPSS 0.37% · 58.5th percentile

Risk Scores

EPSS Score
0.37%
58.5th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSjupyter-notebook0, 4.2.3-4, 5.1.0-2

Timeline

References

Open in Interactive Console →