Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-21699

Опубликовано: 19 янв. 2022
Источник: debian
EPSS Низкий

Описание

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ipythonfixed7.31.1-1package

Примечания

  • https://github.com/ipython/ipython/security/advisories/GHSA-pq7m-3gw7-gq5x

  • Fixed by: https://github.com/ipython/ipython/commit/1ec91ebf328bdf3450130de4b4604c79dc1e19d9

  • Testcase: https://github.com/ipython/ipython/commit/56665dfcf7df8690da46aab1278df8e47b14fe3b

  • https://ipython.readthedocs.io/en/stable/whatsnew/version8.html#ipython-8-0-1-cve-2022-21699

EPSS

Процентиль: 79%
0.01374
Низкий

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 3 лет назад

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

CVSS3: 8.2
nvd
больше 3 лет назад

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

suse-cvrf
почти 3 года назад

Security update for python-ipython

CVSS3: 8.2
github
больше 3 лет назад

Execution with Unnecessary Privileges in ipython

CVSS3: 8.8
fstec
больше 3 лет назад

Уязвимость команды shell командной оболочки для интерактивных вычислений IPython, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 79%
0.01374
Низкий