Vulnerability Name: | CVE-2015-5607 (CCN-105538) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2015-07-12 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2015-07-12 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2017-10-05 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | Cross-site request forgery in the REST API in IPython 2 and 3. | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-352 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-5607 Source: CCN Type: IPython Web site Jupyter and the future of IPython Source: FEDORA Type: Issue Tracking, Third Party Advisory FEDORA-2015-11677 Source: FEDORA Type: Issue Tracking, Third Party Advisory FEDORA-2015-11767 Source: CCN Type: oss-security Mailing List, Tue, 21 Jul 2015 07:50:58 -0400 (EDT) Re: CVE request: IPython CSRF validation Source: CCN Type: oss-security Mailing List, Sun, 12 Jul 2015 15:12:33 -0500 CVE request: IPython CSRF validation Source: MLIST Type: Exploit, Mailing List, Patch, Third Party Advisory [oss-security] 20150721 Re: CVE request: IPython CSRF validation Source: CONFIRM Type: Issue Tracking, Patch https://bugzilla.redhat.com/show_bug.cgi?id=1243842 Source: XF Type: UNKNOWN ipython-cve20155607-csrf(105538) Source: CONFIRM Type: Patch, Third Party Advisory https://github.com/ipython/ipython/commit/1415a9710407e7c14900531813c15ba6165f0816 Source: CONFIRM Type: Patch, Third Party Advisory https://github.com/ipython/ipython/commit/a05fe052a18810e92d9be8c1185952c13fe4e5b0 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-5607 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |