Lucene search

K
ubuntuUbuntuUSN-6153-1
HistoryJun 12, 2023 - 12:00 a.m.

Jupyter Core vulnerability

2023-06-1200:00:00
ubuntu.com
43
jupyter core
ubuntu
untrusted files
arbitrary code
security vulnerability

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.005

Percentile

76.5%

Releases

  • Ubuntu 22.10
  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM

Packages

  • jupyter-core - Core common functionality of Jupyter projects (tools)

Details

It was discovered that Jupyter Core executed untrusted files in the current
working directory. An attacker could possibly use this issue to execute
arbitrary code.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.005

Percentile

76.5%