6.8
CVSSv2

CVE-2018-8768

Published: 18/03/2018 Updated: 19/11/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Jupyter Notebook prior to 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jupyter notebook

Vendor Advisories

Debian Bug report logs - #893436 jupyter-notebook: CVE-2018-8768 Package: src:jupyter-notebook; Maintainer for src:jupyter-notebook is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 18 Mar 2018 20:03:02 UTC Severity: grave Tag ...