CVE-2015-7337

medium
Published 2015-09-29 ยท Modified 2023-11-08
CVSS v3
โ€”
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
6.8

Description

The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.

Predictions

Exploit likelihood
30%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 0
sid Fixed 0
forky Fixed 0
bullseye Fixed 0
bookworm Fixed 0

Package impact

EcosystemPackageVulnerableFixed
python PyPInotebook>=4.0.0,<4.0.54.0.5
python PyPIipython<3.2.23.2.2
python PyPIipython<0a8096adf165e2465550bd5893d7e352544e5967||<3.2.20a8096adf165e2465550bd5893d7e352544e5967
python PyPInotebook<9e63dd89b603dfbe3a7e774d8a962ee0fa30c0b5||>=4.0.0,<4.0.59e63dd89b603dfbe3a7e774d8a962ee0fa30c0b5

Application impact

VendorProductVersionsFixed
ipythonnotebook{"endIncluding":"3.2.1"}
jupyternotebook4.0.0
jupyternotebook4.0.1
jupyternotebook4.0.2
jupyternotebook4.0.3
jupyternotebook4.0.4

References

CWEs

CWE-20

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.