CVE-2015-7337

medium
Published 2015-09-29 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
6.8
VIR risk
6.8

Description

The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-7337

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Package impact

EcosystemPackageVulnerableFixed
python PyPInotebook>=4.0.0,<4.0.54.0.5
python PyPIipython<3.2.23.2.2
python PyPIipython<0a8096adf165e2465550bd5893d7e352544e5967||<3.2.20a8096adf165e2465550bd5893d7e352544e5967
python PyPInotebook<9e63dd89b603dfbe3a7e774d8a962ee0fa30c0b5||>=4.0.0,<4.0.59e63dd89b603dfbe3a7e774d8a962ee0fa30c0b5

Application impact

VendorProductVersionsFixed
ipythonnotebook{"endIncluding":"3.2.1"}
jupyternotebook4.0.0
jupyternotebook4.0.1
jupyternotebook4.0.2
jupyternotebook4.0.3
jupyternotebook4.0.4

References

CWEs

CWE-20

Verify integrity in audit chain (admin only). AS-IS.