CVE-2014-3429

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
07/08/2014
Last modified:
12/04/2025

Description

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:0.12:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:0.12.1:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:0.13:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:0.13.1:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:0.13.2:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:1.1.0:*:*:*:*:*:*:*
cpe:2.3:o:mageia:mageia:3.0:*:*:*:*:*:*:*
cpe:2.3:o:mageia:mageia:4.0:*:*:*:*:*:*:*