CVE-2022-21699
Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.66% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-250, CWE-279, CWE-269
- Affected
- ipython/ipython · debian/debian linux · fedoraproject/fedora
- Source
- security-advisories@github.com
References
- https://github.com/ipython/ipython/commit/46a51ed69cdf41b4333943d9ceeb945c4ede5668Patch, Third Party Advisory
- https://github.com/ipython/ipython/security/advisories/GHSA-pq7m-3gw7-gq5xExploit, Third Party Advisory
- https://ipython.readthedocs.io/en/stable/whatsnew/version8.html#ipython-8-0-1-cve-2022-21699Release Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00021.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CRQRTWHYXMLDJ572VGVUZMUPEOTPM3KB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DZ7LVZBB4D7KVSFNEQUBEHFO3JW6D2ZK/
- https://github.com/ipython/ipython/commit/46a51ed69cdf41b4333943d9ceeb945c4ede5668Patch, Third Party Advisory
- https://github.com/ipython/ipython/security/advisories/GHSA-pq7m-3gw7-gq5xExploit, Third Party Advisory
- https://ipython.readthedocs.io/en/stable/whatsnew/version8.html#ipython-8-0-1-cve-2022-21699Release Notes, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2022/01/msg00021.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CRQRTWHYXMLDJ572VGVUZMUPEOTPM3KB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DZ7LVZBB4D7KVSFNEQUBEHFO3JW6D2ZK/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.