Jupyter Notebook could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7464-1 April 28, 2025 jupyter-notebook vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Jupyter Notebook could be made to crash if it received specially crafted input. Software Description: - jupyter-notebook: Jupyter interactive notebook Details: It was discovered that Jupyter Notebook did not properly parse HTML comments under certain circumstances. An attacker could possibly use this issue to cause a regular expression denial of service (ReDoS). Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 jupyter-notebook 6.4.13-5ubuntu0.1 python3-notebook 6.4.13-5ubuntu0.1 Ubuntu 24.10 jupyter-notebook 6.4.13-2ubuntu0.1 python3-notebook 6.4.13-2ubuntu0.1 Ubuntu 24.04 LTS jupyter-notebook 6.4.12-2.2ubuntu1+esm1 Available with Ubuntu Pro python3-notebook 6.4.12-2.2ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS jupyter-notebook 6.4.8-1ubuntu0.1+esm1 Available with Ubuntu Pro python3-notebook 6.4.8-1ubuntu0.1+esm1 Available with Ubuntu Pro In general, a standard system updatewill make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7464-1 CVE-2022-25887 Package Information: https://launchpad.net/ubuntu/+source/jupyter-notebook/6.4.13-5ubuntu0.1 https://launchpad.net/ubuntu/+source/jupyter-notebook/6.4.13-2ubuntu0.1 . A significant vulnerability in Jupyter Notebook permits system crashes triggered by specially designed input. Ensure you update your Ubuntu packages without delay.. jupyter notebook security, ubuntu vulnerabilities, denial of service, security update. . Severity: Critical. LinuxSecurity.com Team
The package jupyter-notebook before version 5.7.2-1 is vulnerable to cross-site scripting. . Arch Linux Security Advisory ASA-201812-1 ======================================== Severity: Medium Date : 2018-12-06 CVE-ID : CVE-2018-19351 CVE-2018-19352 Package : jupyter-notebook Type : cross-site scripting Remote : No Link : https://security.archlinux.org/AVG-820 Summary ====== The package jupyter-notebook before version 5.7.2-1 is vulnerable to cross-site scripting. Resolution ========= Upgrade to 5.7.2-1. # pacman -Syu "jupyter-notebook> =5.7.2-1" The problems have been fixed upstream in version 5.7.2. Workaround ========= None. Description ========== - CVE-2018-19351 (cross-site scripting) A security issue has been found in Jupyter Notebook versions prior to 5.7.1, where untrusted javascript could be executed if malicious files could be delivered to the users system and the user takes specific actions with those malicious files. It allowed nbconvert endpoints (such as Print Preview) to render untrusted HTML and javascript with access to the notebook server. - CVE-2018-19352 (cross-site scripting) A security issue has been found in Jupyter Notebook versions prior to 5.7.2, where untrusted javascript could be executed if malicious files could be delivered to the users system and the user takes specific actions with those malicious files. It allowed maliciously crafted directory names to execute javascript when opened in the tree view. Impact ===== A remote attacker is able to execute javascript and create html content by tricking users into opening and interacting with maliciously crafted notebook files. References ========= https://bugs.archlinux.org/task/60910 https://security.archlinux.org/CVE-2018-19351 https://security.archlinux.org/CVE-2018-19352 . Follow these steps to update Jupyter Notebook on Arch Linux and address cross-site scripting vulnerabilities effectively and securely. Arch Linux Security,Jupyter Notebook Update,Cross-Site Scripting. . Severity: Medium.LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.