Description
|
|
Two cross-site scripting vulnerabilities have been identified in IPython:
A remote attacker can exploit it by manipulating URL parameters, used in the generation of error messages, in order to execute arbitrary code.
These vulnerabilities, located in /api/contents (CVE-2015-4706) and in /api/notebooks (CVE-2015-4707), are caused by a display of error messages in text/html format, instead of JSON.
Updated, 24/06/2015:
The ipython packages provided by Debian Jessie 8 are vulnerable.
The ipython packages provided by FreeBSD are vulnerable.
|