An XSSI (cross-site inclusion) vulnerability in Jupyter Notebook before 5.7.6 allows inclusion of resources on malicious pages when visited by users who are authenticated with a Jupyter server. Reference: https://security-tracker.debian.org/tracker/CVE-2019-9644 Upstream commit: https://github.com/jupyter/notebook/compare/f3f00df...05aa4b2
Created python-notebook tracking bugs for this issue: Affects: fedora-all [bug 1689856]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.