← volver
CVE-2021-32862highCWE-79

nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths

21Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 7.5epss 1.1%
probabilidad de explotación
1.1%top 37% de las CVE
explotación observada
noninguna fuente lo reporta
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
jupyter · nbconvert