nbgrader@0.9.4 vulnerabilities

A system for assigning and grading notebooks

  • latest version

    0.9.5

  • latest non vulnerable version

  • first published

    9 years ago

  • latest version published

    5 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the nbgrader package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Restriction of Rendered UI Layers or Frames

    nbgrader is an A system for assigning and grading notebooks

    Affected versions of this package are vulnerable to Improper Restriction of Rendered UI Layers or Frames due to the improper configuration of the frame-ancestors directive. An attacker can extract sensitive content by crafting malicious links that embed the vulnerable page in an IFrame, exploiting the same-origin access to execute scripts and extract data.

    How to fix Improper Restriction of Rendered UI Layers or Frames?

    Upgrade nbgrader to version 0.9.5 or higher.

    [0.9.4,0.9.5)