Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-21699

Опубликовано: 19 янв. 2022
Источник: debian

Описание

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ipythonfixed7.31.1-1package

Примечания

  • https://github.com/ipython/ipython/security/advisories/GHSA-pq7m-3gw7-gq5x

  • Fixed by: https://github.com/ipython/ipython/commit/1ec91ebf328bdf3450130de4b4604c79dc1e19d9

  • Testcase: https://github.com/ipython/ipython/commit/56665dfcf7df8690da46aab1278df8e47b14fe3b

  • https://ipython.readthedocs.io/en/stable/whatsnew/version8.html#ipython-8-0-1-cve-2022-21699

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 3 лет назад

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

CVSS3: 8.2
nvd
больше 3 лет назад

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

suse-cvrf
около 3 лет назад

Security update for python-ipython

CVSS3: 8.2
github
больше 3 лет назад

Execution with Unnecessary Privileges in ipython

CVSS3: 8.8
fstec
больше 3 лет назад

Уязвимость команды shell командной оболочки для интерактивных вычислений IPython, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании