CVE-2021-32797
JupyterLab: XSS due to lack of sanitization of the action attribute of an html <form>
7.4
HIGH
CVSS 3.1
EPSS 2.6%
描述
JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affected versions untrusted notebook can execute code on load. In particular JupyterLab doesn’t sanitize the action attribute of html `<form>`. Using this it is possible to trigger the form validation outside of the form itself. This is a remote code execution, but requires user action to open a notebook.
如何修補 CVE-2021-32797
要修補 CVE-2021-32797,請將受影響套件升級到下列已修補版本。
- —升級至 1.2.21 或更新版本
- —升級至 5.7.11 或更新版本
CVE-2021-32797 正在被利用嗎?
低 — EPSS 為 2.6%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1.2.21
- from 0, < 5.7.11
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N |
| osv | CVSS 3.1 | HIGH7.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |