← volver
CVE-2021-32862

nbconvert vulnerable to cross-site scripting (XSS) via multiple exploit paths

CVSS 7.5 HIGHEPSS 1.1%CWE-79
The GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert. When using nbconvert to generate an HTML version of a user-controllable notebook, it is possible to inject arbitrary HTML which may lead to cross-site scripting (XSS) vulnerabilities if these HTML notebooks are served by a web server (eg: nbviewer).
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Productos afectados
jupyter · nbconvert

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →