notebook
notebook copied to clipboard
6.x series is vulnerable to CVE-2019-10856
trafficstars
Describe the bug The 6.x series are vulnerable to CVE-2019-10856.
To Reproduce Steps to reproduce the behavior:
- Set up a notebook server.
- Construct a link to exploit CVE-2019-10856 and open it in Chrome.
- Enter a valid username and password and log in.
Expected behavior The server should refuse to show the login page or to redirect to the malicious website.