Lucene search

K
githubGitHub Advisory DatabaseGHSA-4952-P58Q-6CRX
HistoryAug 23, 2021 - 7:40 p.m.

JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>

2021-08-2319:40:22
CWE-75
CWE-79
CWE-87
GitHub Advisory Database
github.com
26
jupyterlab
xss
html form
remote code execution
action attribute
security patch
owasp
google
software

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS

0.004

Percentile

73.0%

Impact

Untrusted notebook can execute code on load. This is a remote code execution, but requires user action to open a notebook.

Patches

Patched in the following versions: 3.1.4, 3.0.17, 2.3.2, 2.2.10, 1.2.21.

References

OWASP Page on Restricting Form Submissions

For more information

If you have any questions or comments about this advisory, or vulnerabilities to report, please email our security list [email protected].

Credit: Guillaume Jeanne from Google

Affected configurations

Vulners
Node
jupyterlabjupyterlabRange3.1.0a03.1.4
OR
jupyterlabjupyterlabRange3.0.0a03.0.17
OR
jupyterlabjupyterlabRange2.3.0a02.3.2
OR
jupyterlabjupyterlabRange2.0.0a02.2.10
OR
notebookRange6.0.06.4.1
OR
notebookRange<5.7.11
OR
jupyterlabjupyterlabRange<1.2.21
VendorProductVersionCPE
jupyterlabjupyterlab*cpe:2.3:a:jupyterlab:jupyterlab:*:*:*:*:*:*:*:*
*notebook*cpe:2.3:a:*:notebook:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

9.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS

0.004

Percentile

73.0%