Lucene search

K
cvelistGitHub_MCVELIST:CVE-2022-21699
HistoryJan 19, 2022 - 9:15 p.m.

CVE-2022-21699 Execution with Unnecessary Privileges in ipython

2022-01-1921:15:11
CWE-279
CWE-250
GitHub_M
www.cve.org
6
ipython
arbitrary code execution
cross user files

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

29.4%

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

CNA Affected

[
  {
    "product": "ipython",
    "vendor": "ipython",
    "versions": [
      {
        "status": "affected",
        "version": "< 5.11"
      },
      {
        "status": "affected",
        "version": ">= 6.0.0, < 7.16.3"
      },
      {
        "status": "affected",
        "version": ">= 7.17.0, < 7.31.1"
      },
      {
        "status": "affected",
        "version": ">= 8.0.0, < 8.0.1"
      }
    ]
  }
]

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

29.4%