Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Thu, 31 Jul 2014 23:23:18 -0500
From: Kyle Kelley <>
Cc:, IPython developers list <>
Subject: CVE Request: Enforce use of HTTPS for MathJax in IPython


We would like to request a CVE for a vulnerability in the IPython notebook,
reported today by Leopold Schabel on IPython's GitHub issue tracker at

Email address of requester:;
Software name: IPython notebook
Type of vulnerability: Use of insecure resources
Attack outcome: Remote execution
Affected versions: 0.12 ≤ version ≤ 2.1

Summary: When using the IPython notebook without encryption (i.e. running
the server on HTTP instead of HTTPS), mathjax is loaded over HTTP. An
attacker with fortuitous network position could execute code on a local
IPython notebook by modifying the mathjax javascript.

This issue was fixed in the git master branch (development branch for
upcoming v. 2.2) with commit cf793ebc4, on 7/31/2014:

* Run the notebook with SSL (see
* Install mathjax
    from IPython.external.mathjax import install_mathjax


Kyle Kelley

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.