CVE-2022-21699
Summary
| CVE | CVE-2022-21699 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-19 22:15:00 UTC |
| Updated | 2023-11-07 03:43:00 UTC |
| Description | IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade. |
Risk And Classification
Problem Types: CWE-250 | CWE-279
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Application | Ipython | Ipython | All | All | All | All |
| Application | Ipython | Ipython | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] Fedora 35 Update: ipython-7.26.0-3.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 34 Update: ipython-7.20.0-2.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] [DLA 2896-1] ipython security update | MLIST | lists.debian.org | |
| Execution with Unnecessary Privileges in ipython · Advisory · ipython/ipython · GitHub | CONFIRM | github.com | |
| [SECURITY] Fedora 35 Update: ipython-7.26.0-3.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| 8.x Series — IPython 8.0.0 documentation | MISC | ipython.readthedocs.io | |
| [SECURITY] Fedora 34 Update: ipython-7.20.0-2.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| Merge pull request from GHSA-pq7m-3gw7-gq5x · ipython/ipython@46a51ed · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179028 Debian Security Update for ipython (DLA 2896-1)
- 179046 Debian Security Update for ipython (DSA 5065-1)
- 184542 Debian Security Update for ipython (CVE-2022-21699)
- 199529 Ubuntu Security Notification for IPython Vulnerabilities (USN-5953-1)
- 282374 Fedora Security Update for ipython (FEDORA-2022-b9e38f8a56)
- 282375 Fedora Security Update for ipython (FEDORA-2022-b58d156ab0)
- 502308 Alpine Linux Security Update for ipython
- 690983 Free Berkeley Software Distribution (FreeBSD) Security Update for ipython (35d1e192-628e-11ed-8c5e-641c67a117d8)