Candidate: CVE-2018-21030 PublicDate: 2019-10-31 15:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-21030 https://github.com/jupyter/notebook/pull/3341 https://github.com/jupyter/notebook/releases/tag/5.5.0 Description: Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N [5.3 MEDIUM] Patches_jupyter-notebook: upstream_jupyter-notebook: released (5.5.0, 4.2.3-4+deb9u1, 5.7.4-1) precise/esm_jupyter-notebook: DNE trusty_jupyter-notebook: ignored (out of standard support) trusty/esm_jupyter-notebook: DNE xenial_jupyter-notebook: DNE bionic_jupyter-notebook: needed disco_jupyter-notebook: not-affected (5.7.4-1) eoan_jupyter-notebook: not-affected (5.7.8-1) focal_jupyter-notebook: not-affected (5.7.8-1) groovy_jupyter-notebook: not-affected (5.7.8-1) hirsute_jupyter-notebook: not-affected (5.7.8-1) impish_jupyter-notebook: not-affected (5.7.8-1) jammy_jupyter-notebook: not-affected (5.7.8-1) devel_jupyter-notebook: not-affected (5.7.8-1)