Skip to content

CVE-2014-3429

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0209 (2.1%)
Percentile: 84.1%
EPSS: 2026-05-06

Affects

opensuse:opensuseipython:ipython_notebookmageia:mageia

Technical description

IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.

Published: 8/7/2014, 11:13:34 AM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam