Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian 11: DLA-3863-1 Critical: Nbconvert XSS Risks Require Attention

debian lts
Calendar Grey September 2, 2024
Dist Debian Esm H88
The DLA-4872-3 notice outlines critical SQL injection issues within the DataHandler module, recommending an immediate patch for user protection.
Alvaro Muñoz from the GitHub Security Lab discovered sixteen ways to exploit a cross-site scripting vulnerability in nbconvert, a tool and library used to convert notebooks to v...

Summary

When using nbconvert to generate an HTML version of a user-controllable
notebook, it is possible to inject arbitrary HTML which may lead to
cross-site scripting (XSS) vulnerabilities if these HTML notebooks are
served by a web server without tight Content-Security-Policy (e.g.,
nbviewer).

* GHSL-2021-1013: XSS in notebook.metadata.language_info.pygments_lexer;
* GHSL-2021-1014: XSS in notebook.metadata.title;
* GHSL-2021-1015: XSS in notebook.metadata.widgets;
* GHSL-2021-1016: XSS in notebook.cell.metadata.tags;
* GHSL-2021-1017: XSS in output data text/html cells;
* GHSL-2021-1018: XSS in output data image/svg+xml cells;
* GHSL-2021-1019: XSS in notebook.cell.output.svg_filename;
* GHSL-2021-1020: XSS in output data text/markdown cells;
* GHSL-2021-1021: XSS in output data application/javascript cells;
* GHSL-2021-1022: XSS in output.metadata.filenames image/png and
image/jpeg;
* GHSL-2021-1023: XSS in output data image/png and image/jpeg cells;

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: nbconvert
Version: 5.6.1-3+deb11u1
CVE ID: CVE-2021-32862

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here