First published: Wed Nov 03 2021(Updated: )
### Impact Improper handling of user controlled input caused a stored cross-site scripting (XSS) vulnerability. All previous versions of nbdime are affected. ### Patches Security patches will be released for each of the major versions of the nbdime packages since version 1.x of the nbdime python package. #### Python - nbdime 1.x: Patched in v. 1.1.1 - nbdime 2.x: Patched in v. 2.1.1 - nbdime 3.x: Patched in v. 3.1.1 #### npm - nbdime 6.x version: Patched in 6.1.2 - nbdime 5.x version: Patched in 5.0.2 - nbdime-jupyterlab 1.x version: Patched in 1.0.1 - nbdime-jupyterlab 2.x version: Patched in 2.1.1 ### For more information If you have any questions or comments about this advisory email us at [security@ipython.org](mailto:security@ipython.org).
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jupyter Nbdime | >=1.0.0<1.1.1 | |
Jupyter Nbdime | >=2.0.0<2.1.1 | |
Jupyter Nbdime | >=3.0.0<=3.1.1 | |
Jupyter Nbdime | >=5.0.0<5.0.2 | |
Jupyter Nbdime | >=6.0.0<6.1.2 | |
Jupyter Nbdime-jupyterlab | >=1.0.0<1.0.1 | |
Jupyter Nbdime-jupyterlab | >=2.0.0<2.1.1 | |
npm/nbdime-jupyterlab | >=2.0.0<2.1.1 | 2.1.1 |
npm/nbdime-jupyterlab | <1.0.1 | 1.0.1 |
npm/nbdime | >=6.0.0<6.1.2 | 6.1.2 |
npm/nbdime | <5.0.2 | 5.0.2 |
pip/nbdime | >=3.0.0<3.1.1 | 3.1.1 |
pip/nbdime | >=2.0.0<2.1.1 | 2.1.1 |
pip/nbdime | <1.1.1 | 1.1.1 |
>=1.0.0<1.1.1 | ||
>=2.0.0<2.1.1 | ||
>=3.0.0<=3.1.1 | ||
>=5.0.0<5.0.2 | ||
>=6.0.0<6.1.2 | ||
>=1.0.0<1.0.1 | ||
>=2.0.0<2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41134 is a stored cross-site scripting (XSS) vulnerability in the Jupyter Nbdime project.
Versions 1.0.0 to 1.1.1, 2.0.0 to 2.1.1, 3.0.0 to 3.1.1 of nbdime are affected by CVE-2021-41134.
CVE-2021-41134 has a severity score of 5.4 (high).
To fix CVE-2021-41134, upgrade to a version of nbdime that is not affected by the vulnerability.
You can find more information about CVE-2021-41134 in the Jupyter Nbdime project's GitHub repository and security advisories.