CVE-2014-3429

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:ipython:ipython_notebook:0.12:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:0.12.1:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:0.13:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:0.13.1:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:0.13.2:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ipython:ipython_notebook:1.1.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:mageia:mageia:3.0:*:*:*:*:*:*:*
cpe:2.3:o:mageia:mageia:4.0:*:*:*:*:*:*:*

History

21 Nov 2024, 02:08

Type Values Removed Values Added
References () http://advisories.mageia.org/MGASA-2014-0320.html - Third Party Advisory () http://advisories.mageia.org/MGASA-2014-0320.html - Third Party Advisory
References () http://lambdaops.com/cross-origin-websocket-hijacking-of-ipython - Press/Media Coverage, Technical Description () http://lambdaops.com/cross-origin-websocket-hijacking-of-ipython - Press/Media Coverage, Technical Description
References () http://lists.opensuse.org/opensuse-updates/2014-08/msg00039.html - Third Party Advisory () http://lists.opensuse.org/opensuse-updates/2014-08/msg00039.html - Third Party Advisory
References () http://permalink.gmane.org/gmane.comp.python.ipython.devel/13198 - Broken Link () http://permalink.gmane.org/gmane.comp.python.ipython.devel/13198 - Broken Link
References () http://seclists.org/oss-sec/2014/q3/152 - Third Party Advisory, VDB Entry () http://seclists.org/oss-sec/2014/q3/152 - Third Party Advisory, VDB Entry
References () http://www.mandriva.com/security/advisories?name=MDVSA-2015:160 - Broken Link () http://www.mandriva.com/security/advisories?name=MDVSA-2015:160 - Broken Link
References () https://bugzilla.redhat.com/show_bug.cgi?id=1119890 - Issue Tracking () https://bugzilla.redhat.com/show_bug.cgi?id=1119890 - Issue Tracking
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/94497 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/94497 -
References () https://github.com/ipython/ipython/pull/4845 - Patch, Issue Tracking () https://github.com/ipython/ipython/pull/4845 - Issue Tracking, Patch

Information

Published : 2014-08-07 11:13

Updated : 2024-11-21 02:08


NVD link : CVE-2014-3429

Mitre link : CVE-2014-3429

CVE.ORG link : CVE-2014-3429


JSON object : View

Products Affected

opensuse

  • opensuse

ipython

  • ipython_notebook

mageia

  • mageia
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')