« Volver al listado

CVE-2014-3429

Estado: ModificadaMedia (6.8)—

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-3429",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-08-07T11:13:34.843",
  "references": [
    {
      "url": "http://advisories.mageia.org/MGASA-2014-0320.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lambdaops.com/cross-origin-websocket-hijacking-of-ipython",
      "tags": [
        "Press/Media Coverage",
        "Technical Description"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-08/msg00039.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://permalink.gmane.org/gmane.comp.python.ipython.devel/13198",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/oss-sec/2014/q3/152",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:160",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1119890",
      "tags": [
        "Issue Tracking"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/94497",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/ipython/ipython/pull/4845",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://advisories.mageia.org/MGASA-2014-0320.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lambdaops.com/cross-origin-websocket-hijacking-of-ipython",
      "tags": [
        "Press/Media Coverage",
        "Technical Description"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-08/msg00039.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://permalink.gmane.org/gmane.comp.python.ipython.devel/13198",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/oss-sec/2014/q3/152",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:160",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1119890",
      "tags": [
        "Issue Tracking"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/94497",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/ipython/ipython/pull/4845",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page."
    },
    {
      "lang": "es",
      "value": "IPython Notebook 0.12 hasta 1.x anterior a 1.2 no valida el origen de las solicitudes de Websockets, lo que permite a atacantes remotos ejecutar código arbitrario mediante el aprovechamiento de conocimiento del kernel id y una página manipulada."
    }
  ],
  "lastModified": "2026-06-17T00:08:10.127",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A10BC294-9196-425F-9FB0-B1625465B47F"
            },
            {
              "criteria": "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "03117DF1-3BEC-4B8D-AD63-DBBDB2126081"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ipython:ipython_notebook:0.12:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6334C8B2-6F96-4277-B4E8-9A6538EDA6D2"
            },
            {
              "criteria": "cpe:2.3:a:ipython:ipython_notebook:0.12.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "38C7D06C-C68E-484A-B3BB-B675F07A43C1"
            },
            {
              "criteria": "cpe:2.3:a:ipython:ipython_notebook:0.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "245FA6D3-3BBC-4B5B-9EBF-A8332263A2FD"
            },
            {
              "criteria": "cpe:2.3:a:ipython:ipython_notebook:0.13.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "217B34EF-6ADB-43F3-A132-F396371F7201"
            },
            {
              "criteria": "cpe:2.3:a:ipython:ipython_notebook:0.13.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4EFBF65E-53AE-45E1-A38B-4FB993C48624"
            },
            {
              "criteria": "cpe:2.3:a:ipython:ipython_notebook:1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08D341C5-ECE9-40DA-9E48-A496A8407701"
            },
            {
              "criteria": "cpe:2.3:a:ipython:ipython_notebook:1.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "764B1A0F-CCF0-47CD-A477-05FF2FF82E4A"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:mageia:mageia:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76F1E356-E019-47E8-AA5F-702DA93CF74E"
            },
            {
              "criteria": "cpe:2.3:o:mageia:mageia:4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F805A106-9A6F-48E7-8582-D3C5A26DFC11"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}