CVE-2018-8768

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/03/2018
Last modified:
19/11/2020

Description

In Jupyter Notebook before 5.4.1, a maliciously forged notebook file can bypass sanitization to execute JavaScript in the notebook context. Specifically, invalid HTML is 'fixed' by jQuery after sanitization, making it dangerous.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jupyter:notebook:*:*:*:*:*:*:*:* 5.4.1 (excluding)