Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m678-f26j-3hrp

Опубликовано: 26 окт. 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Execution with Unnecessary Privileges in JupyterApp

Impact

What kind of vulnerability is it? Who is impacted? We’d like to disclose an arbitrary code execution vulnerability in jupyter_core that stems from jupyter_core executing untrusted files in the current working directory. This vulnerability allows one user to run code as another.

Patches

Has the problem been patched? What versions should users upgrade to? Users should upgrade to jupyter_core>=4.11.2.

Workarounds

Is there a way for users to fix or remediate the vulnerability without upgrading? No

References

Are there any links users can visit to find out more? Similar advisory in IPython

Пакеты

Наименование

jupyter-core

pip
Затронутые версииВерсия исправления

< 4.11.2

4.11.2

EPSS

Процентиль: 57%
0.00356
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-250
CWE-269
CWE-427

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 3 лет назад

Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.

CVSS3: 8.8
nvd
около 3 лет назад

Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.

CVSS3: 8.8
debian
около 3 лет назад

Jupyter Core is a package for the core common functionality of Jupyter ...

CVSS3: 8.8
fstec
больше 2 лет назад

Уязвимость ядра Jupyter Core среды интерактивной разработки и выполнения кода Jupyter Notebook, позволяющая нарушителю раскрыть защищаемую информацию, загружать и выполнять код с повышенными привилегиями

CVSS3: 8.8
redos
около 1 месяца назад

Уязвимость python2-jupyter-core

EPSS

Процентиль: 57%
0.00356
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-250
CWE-269
CWE-427