Safety vulnerability ID: 40388
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Notebook 4.2.2 includes a fix for CVE-2016-6524: Untrusted LaTeX output could be added to the page in a way that could execute javascript.
Latest version: 7.3.2
Jupyter Notebook - A web-based notebook environment for interactive computing
4.2.2 is a small bugfix release on 4.2, with an important security fix.
All users are strongly encouraged to upgrade to 4.2.2.
> Highlights:
- **Security fix**: CVE-2016-6524, where untrusted latex output could
be added to the page in a way that could execute javascript.
- Fix missing POST in OPTIONS responses.
- Fix for downloading non-ascii filenames.
- Avoid clobbering ssl_options, so that users can specify more
detailed SSL configuration.
- Fix inverted load order in nbconfig, so user config has highest
priority.
- Improved error messages here and there.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application