Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-6938


Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccurate.


Published

2015-09-21T19:59:05.353

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jupyter notebook 4.0.0 Yes
Application jupyter notebook 4.0.1 Yes
Application jupyter notebook 4.0.2 Yes
Application jupyter notebook 4.0.3 Yes
Application jupyter notebook 4.0.4 Yes
Operating System fedoraproject fedora 21 Yes
Operating System fedoraproject fedora 22 Yes
Operating System fedoraproject fedora 23 Yes
Operating System opensuse opensuse 13.1 Yes
Operating System opensuse opensuse 13.2 Yes
Application ipython notebook ≤ 3.2.1 Yes

References