CVE-2014-3429
CVE-2014-3429
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://advisories.mageia.org/MGASA-2014-0320.htmlhttp://lambdaops.com/cross-origin-websocket-hijacking-of-ipythonhttp://lists.opensuse.org/opensuse-updates/2014-08/msg00039.htmlhttp://permalink.gmane.org/gmane.comp.python.ipython.devel/13198https://bugzilla.redhat.com/show_bug.cgi?id=1119890http://seclists.org/oss-sec/2014/q3/152https://exchange.xforce.ibmcloud.com/vulnerabilities/94497https://github.com/ipython/ipython/pull/4845http://www.mandriva.com/security/advisories?name=MDVSA-2015:160