5.3
CVSSv3

CVE-2018-21030

Published: 31/10/2019 Updated: 19/11/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Jupyter Notebook prior to 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jupyter notebook

Vendor Advisories

Several security issues were fixed in Jupyter Notebook ...