Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37699
HistoryOct 27, 2022 - 4:34 a.m.

Arbitrary Code Execution

2022-10-2704:34:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5
jupyter_core
arbitrary code execution
vulnerability
config file paths
application.py
untrusted files

0.005 Low

EPSS

Percentile

75.5%

jupyter_core is vulnerable to arbitrary code execution. The vulnerability exists in the config_file_paths function in application.py which executes untrusted files in the current working directory, allowing one user to run code as another.