CVE-2019-9644

unknown
Published 2022-05-14 · Modified 2023-11-08
CVSS v3
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CVSS v2
VIR risk

Description

An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Access to the content of resources has been demonstrated with Internet Explorer through capturing of error messages, though not reproduced with other browsers. This occurs because Internet Explorer's error messages can include the content of any invalid JavaScript that was encountered.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2019-9644

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed5.7.8-1
debian debianbullseyefixed5.7.8-1
debian debianforkyfixed5.7.8-1
debian debiansidfixed5.7.8-1
debian debiantrixiefixed5.7.8-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIjupyter-notebook<5.7.65.7.6
python PyPInotebook<5.7.65.7.6

References

Verify integrity in audit chain (admin only). AS-IS.