| ID | CVE-2018-21030 | ||||||
| Sažetak | Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document. | ||||||
| Reference | |||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | AV:N/AC:L/Au:N/C:N/I:P/A:N | ||||||
| Zadnje važnije ažuriranje | 19-11-2020 - 07:15 | ||||||
| Objavljeno | 31-10-2019 - 15:15 |

