← Back to CVE List

CVE-2018-21030

Published: 2019-10-31T15:15Z
Last Modified: 2024-11-21T04:02Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt