oss-sec mailing list archives
CVE Request: Enforce use of HTTPS for MathJax in IPython
From: Kyle Kelley <rgbkrk () gmail com>
Date: Thu, 31 Jul 2014 23:23:18 -0500
All, We would like to request a CVE for a vulnerability in the IPython notebook, reported today by Leopold Schabel on IPython's GitHub issue tracker at https://github.com/ipython/ipython/issues/6246. Email address of requester: security () ipython org; rgbkrk () gmail com Software name: IPython notebook Type of vulnerability: Use of insecure resources Attack outcome: Remote execution Patch/issue: https://github.com/ipython/ipython/pull/6249, https://github.com/ipython/ipython/issues/6246 Affected versions: 0.12 ≤ version ≤ 2.1 Summary: When using the IPython notebook without encryption (i.e. running the server on HTTP instead of HTTPS), mathjax is loaded over HTTP. An attacker with fortuitous network position could execute code on a local IPython notebook by modifying the mathjax javascript. This issue was fixed in the git master branch (development branch for upcoming v. 2.2) with commit cf793ebc4, on 7/31/2014: https://github.com/ipython/ipython/commit/cf793ebc4f9e8483f104667e4c73748357fa8c56 Mitigations: * Run the notebook with SSL (see http://ipython.org/ipython-doc/2/notebook/public_server.html#securing-a-notebook-server ). * Install mathjax from IPython.external.mathjax import install_mathjax install_mathjax() Regards, Kyle Kelley
Current thread:
- CVE Request: Enforce use of HTTPS for MathJax in IPython Kyle Kelley (Jul 31)
- Re: CVE Request: Enforce use of HTTPS for MathJax in IPython gremlin (Aug 02)
- Re: CVE Request: Enforce use of HTTPS for MathJax in IPython Donald Stufft (Aug 02)
- Re: CVE Request: Enforce use of HTTPS for MathJax in IPython Kurt Seifried (Aug 02)
- Re: CVE Request: Enforce use of HTTPS for MathJax in IPython gremlin (Aug 03)
- Re: CVE Request: Enforce use of HTTPS for MathJax in IPython Donald Stufft (Aug 03)
- Re: CVE Request: Enforce use of HTTPS for MathJax in IPython gremlin (Aug 05)
- Re: CVE Request: Enforce use of HTTPS for MathJax in IPython Donald Stufft (Aug 02)
- Re: CVE Request: Enforce use of HTTPS for MathJax in IPython gremlin (Aug 02)
- Re: CVE Request: Enforce use of HTTPS for MathJax in IPython gremlin (Aug 02)
- Re: CVE Request: Enforce use of HTTPS for MathJax in IPython Donald Stufft (Aug 03)