← Back

CVE-2014-3429

nvd nist
Published: Aug 7, 2014Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.

Affected (11)

1 product
Opensuse
1 product
Ipython Notebook
1 product
Mageia
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Opensuse
Version 13.1
Version 13.2
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Ipython
Version 0.12.1
Version 0.12
Version 0.13.1
Version 0.13.2
Version 0.13
Version 1.0.0
Version 1.1.0
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Mageia
Version 3.0
Version 4.0

References (18)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Press/Media CoverageTechnical Description
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Press/Media CoverageTechnical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch

Timeline

No history available yet.