CVE-2021-32798: Special Element Injection in notebook
(updated )
Untrusted notebook can execute code on load. This is a remote code execution, but requires user action to open a notebook.
References
- github.com/advisories/GHSA-hwvq-6gjx-j797
- github.com/jupyter/notebook
- github.com/jupyter/notebook/commit/79fc76e890a8ec42f73a3d009e44ef84c14ef0d5
- github.com/jupyter/notebook/security/advisories/GHSA-hwvq-6gjx-j797
- github.com/pypa/advisory-database/tree/main/vulns/notebook/PYSEC-2021-118.yaml
- nvd.nist.gov/vuln/detail/CVE-2021-32798
Detect and mitigate CVE-2021-32798 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →