CVE-2018-19352: XSS
Published Nov 18, 2018
·Updated
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
Affected Software
2 affected componentsFixes available
jupyter notebook<5.7.2
pip/notebook<5.7.2
5.7.2
Remediation
Event History
Nov 18, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Nov 21, 2018
Advisory Published
10:19 PM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-19352.
2
What is the severity of CVE-2018-19352?
The severity of CVE-2018-19352 is medium (6.1).
3
How does Jupyter Notebook before 5.7.2 allow XSS?
Jupyter Notebook before 5.7.2 allows XSS via a crafted directory name because notebook/static/tree/js/notebooklist.js handles certain URLs unsafely.
4
Which software versions are affected by CVE-2018-19352?
Jupyter Notebook versions up to, but not including, 5.7.2 are affected by CVE-2018-19352.
5
How can I fix CVE-2018-19352?
To fix CVE-2018-19352, update Jupyter Notebook to version 5.7.2 or newer.