CVE-2022-39286
Summary
| CVE | CVE-2022-39286 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-26 20:15:00 UTC |
| Updated | 2023-11-07 03:50:00 UTC |
| Description | Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 36 Update: python-jupyter-core-4.9.1-3.fc36 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Merge pull request from GHSA-m678-f26j-3hrp · jupyter/jupyter_core@1118c8c · GitHub |
MISC |
github.com |
|
| Debian -- Security Information -- DSA-5422-1 jupyter-core |
DEBIAN |
www.debian.org |
|
| [SECURITY] Fedora 37 Update: python-jupyter-core-4.10.0-4.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| jupyter_core: Arbitrary Code Execution (GLSA 202301-04) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| [SECURITY] [DLA 3195-1] jupyter-core security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 36 Update: python-jupyter-core-4.9.1-3.fc36 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 37 Update: python-jupyter-core-4.10.0-4.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Execution with Unnecessary Privileges in JupyterApp · Advisory · jupyter/jupyter_core · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181224 Debian Security Update for jupyter-core (DLA 3195-1)
- 181837 Debian Security Update for jupyter-core (DSA 5422-1)
- 199552 Ubuntu Security Notification for Jupyter Core Vulnerability (USN-6153-1)
- 283649 Fedora Security Update for python (FEDORA-2023-d966145959)
- 283650 Fedora Security Update for python (FEDORA-2023-de87bd076b)
- 710699 Gentoo Linux jupyter_core Arbitrary Code Execution Vulnerability (GLSA 202301-04)