CVE-2021-32797
Description
JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesnt sanitize the action attribute of html . Using this it is possible to trigger the form validation outside of the form itself. This is a remote code execution, but requires user action to open a notebook.
Risk Information
Base Score
9.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.136
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1 | Windows |
| Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2 | Windows |
| Vulnerabilities CVE-2021-32797,CVE-2021-32798 are fixed in Python-notebook 5.7.11 | Windows |
| Vulnerabilities CVE-2021-32797,CVE-2021-32798 are fixed in Python-notebook 6.4.1 | Windows |
| Vulnerabilities CVE-2021-32797 are fixed in Python-jupyterlab 1.2.21 | Windows |
| Vulnerabilities CVE-2021-32797 are fixed in Python-jupyterlab 2.2.10 | Windows |
| Vulnerabilities CVE-2021-32797 are fixed in Python-jupyterlab 2.3.2 | Windows |
| Vulnerabilities CVE-2021-32797 are fixed in Python-jupyterlab 3.0.17 | Windows |
| Vulnerabilities CVE-2021-32797 are fixed in Python-jupyterlab 3.1.4 | Windows |
| Vulnerabilities CVE-2021-32797,CVE-2021-32798 are fixed in Python-notebook for linux 5.7.11 | Linux |
| Vulnerabilities CVE-2021-32797,CVE-2021-32798 are fixed in Python-notebook for linux 6.4.1 | Linux |
| Vulnerabilities CVE-2021-32797 are fixed in Python-jupyterlab for linux 1.2.21 | Linux |
| Vulnerabilities CVE-2021-32797 are fixed in Python-jupyterlab for linux 2.2.10 | Linux |
| Vulnerabilities CVE-2021-32797 are fixed in Python-jupyterlab for linux 2.3.2 | Linux |
| Vulnerabilities CVE-2021-32797 are fixed in Python-jupyterlab for linux 3.0.17 | Linux |
| Vulnerabilities CVE-2021-32797 are fixed in Python-jupyterlab for linux 3.1.4 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234