CVE-2026-21883 (CNNVD-202601-1569)
中文标题:
bokeh 安全漏洞
英文标题:
Bokeh server applications have Incomplete Origin Validation in WebSockets
漏洞描述
中文描述:
bokeh是Bokeh开源的一个数据可视化的Python库。 bokeh 3.8.1及之前版本存在安全漏洞,该漏洞源于允许列表配置不当,可能导致攻击者与Bokeh服务器交互。
英文描述:
Bokeh is an interactive visualization library written in Python. In versions 3.8.1 and below, if a server is configured with an allowlist (e.g., dashboard.corp), an attacker can register a domain like dashboard.corp.attacker.com (or use a subdomain if applicable) and lure a victim to visit it. The malicious site can then initiate a WebSocket connection to the vulnerable Bokeh server. Since the Origin header (e.g., http://dashboard.corp.attacker.com/) matches the allowlist according to the flawed logic, the connection is accepted. Once connected, the attacker can interact with the Bokeh server on behalf of the victim, potentially accessing sensitive data, or modifying visualizations. This issue is fixed in version 3.8.2.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| bokeh | bokeh | < 3.8.2 | - | - |
cpe:2.3:a:bokeh:bokeh:<_3.8.2:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2026-21883 |
2026-01-09 02:02:08 | 2026-01-12 02:12:38 |
| NVD | nvd_CVE-2026-21883 |
2026-01-09 03:00:09 | 2026-01-12 02:28:17 |
| CNNVD | cnnvd_CNNVD-202601-1569 |
2026-01-11 06:15:10 | 2026-01-12 02:38:15 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202601-1569
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']