Loading
Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.
Use CWE-79, Jupyter vendor hub and Notebook product page to widen CVE-2018-21030 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-32798, CVE-2024-43805 and CVE-2024-22421 for nearby disclosures in the same product family.