CVE-2014-3429
Estado: ModificadaMedia (6.8)—
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Puntuación base: 6.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.70%
- Percentil entre todas las CVEs puntuadas: 92
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-94
Referencias
- http://advisories.mageia.org/MGASA-2014-0320.html
- http://lambdaops.com/cross-origin-websocket-hijacking-of-ipython
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00039.html
- http://permalink.gmane.org/gmane.comp.python.ipython.devel/13198
- http://seclists.org/oss-sec/2014/q3/152
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:160
- https://bugzilla.redhat.com/show_bug.cgi?id=1119890
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94497
- https://github.com/ipython/ipython/pull/4845
- http://advisories.mageia.org/MGASA-2014-0320.html
- http://lambdaops.com/cross-origin-websocket-hijacking-of-ipython
- http://lists.opensuse.org/opensuse-updates/2014-08/msg00039.html
- http://permalink.gmane.org/gmane.comp.python.ipython.devel/13198
- http://seclists.org/oss-sec/2014/q3/152
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:160
- https://bugzilla.redhat.com/show_bug.cgi?id=1119890
- https://exchange.xforce.ibmcloud.com/vulnerabilities/94497
- https://github.com/ipython/ipython/pull/4845
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-3429",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-08-07T11:13:34.843",
"references": [
{
"url": "http://advisories.mageia.org/MGASA-2014-0320.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://lambdaops.com/cross-origin-websocket-hijacking-of-ipython",
"tags": [
"Press/Media Coverage",
"Technical Description"
],
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-08/msg00039.html",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://permalink.gmane.org/gmane.comp.python.ipython.devel/13198",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/oss-sec/2014/q3/152",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:160",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1119890",
"tags": [
"Issue Tracking"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/94497",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/ipython/ipython/pull/4845",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://advisories.mageia.org/MGASA-2014-0320.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lambdaops.com/cross-origin-websocket-hijacking-of-ipython",
"tags": [
"Press/Media Coverage",
"Technical Description"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-08/msg00039.html",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://permalink.gmane.org/gmane.comp.python.ipython.devel/13198",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/oss-sec/2014/q3/152",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2015:160",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1119890",
"tags": [
"Issue Tracking"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/94497",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/ipython/ipython/pull/4845",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page."
},
{
"lang": "es",
"value": "IPython Notebook 0.12 hasta 1.x anterior a 1.2 no valida el origen de las solicitudes de Websockets, lo que permite a atacantes remotos ejecutar código arbitrario mediante el aprovechamiento de conocimiento del kernel id y una página manipulada."
}
],
"lastModified": "2026-06-17T00:08:10.127",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A10BC294-9196-425F-9FB0-B1625465B47F"
},
{
"criteria": "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "03117DF1-3BEC-4B8D-AD63-DBBDB2126081"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ipython:ipython_notebook:0.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6334C8B2-6F96-4277-B4E8-9A6538EDA6D2"
},
{
"criteria": "cpe:2.3:a:ipython:ipython_notebook:0.12.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38C7D06C-C68E-484A-B3BB-B675F07A43C1"
},
{
"criteria": "cpe:2.3:a:ipython:ipython_notebook:0.13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "245FA6D3-3BBC-4B5B-9EBF-A8332263A2FD"
},
{
"criteria": "cpe:2.3:a:ipython:ipython_notebook:0.13.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "217B34EF-6ADB-43F3-A132-F396371F7201"
},
{
"criteria": "cpe:2.3:a:ipython:ipython_notebook:0.13.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4EFBF65E-53AE-45E1-A38B-4FB993C48624"
},
{
"criteria": "cpe:2.3:a:ipython:ipython_notebook:1.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "08D341C5-ECE9-40DA-9E48-A496A8407701"
},
{
"criteria": "cpe:2.3:a:ipython:ipython_notebook:1.1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "764B1A0F-CCF0-47CD-A477-05FF2FF82E4A"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:mageia:mageia:3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "76F1E356-E019-47E8-AA5F-702DA93CF74E"
},
{
"criteria": "cpe:2.3:o:mageia:mageia:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F805A106-9A6F-48E7-8582-D3C5A26DFC11"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}