[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

254802

 
 

909

 
 

198617

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2022-21699Date: (C)2022-01-21   (M)2023-12-22


IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 8.8CVSS Score : 4.6
Exploit Score: 2.0Exploit Score: 3.9
Impact Score: 6.0Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: PARTIAL
Scope: CHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
FEDORA-2022-b58d156ab0
FEDORA-2022-b9e38f8a56
https://lists.debian.org/debian-lts-announce/2022/01/msg00021.html
https://github.com/ipython/ipython/commit/46a51ed69cdf41b4333943d9ceeb945c4ede5668
https://github.com/ipython/ipython/security/advisories/GHSA-pq7m-3gw7-gq5x
https://ipython.readthedocs.io/en/stable/whatsnew/version8.html#ipython-8-0-1-cve-2022-21699

CPE    2
cpe:/o:debian:debian_linux:9.0
cpe:/a:ipython:ipython
CWE    1
CWE-250
OVAL    4
oval:org.secpod.oval:def:78160
oval:org.secpod.oval:def:121631
oval:org.secpod.oval:def:121635
oval:org.secpod.oval:def:605776
...

© SecPod Technologies