Arbitrary Code Execution Affecting ipython package, versions [,3.2.2)
Threat Intelligence
EPSS
1.52% (88th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-IPYTHON-40724
- published 4 Dec 2017
- disclosed 29 Sep 2015
- credit Unknown
Introduced: 29 Sep 2015
CVE-2015-7337 Open this link in a new tabHow to fix?
Upgrade ipython
to version 3.2.2 or higher.
Overview
Affected versions of ipython
are vulnerable to Arbitrary Code Executionhttps://nvd.nist.gov/vuln/detail/CVE-2015-7337.
The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/, related to MIME types.
References
CVSS Scores
version 3.1