CVE-2022-21699

Description

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS Score
Exploitation Probability
1.461

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.4Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 12.0.3Windows
Vulnerabilities CVE-2022-21699 are fixed in Python-ipython 5.11Windows
Vulnerabilities CVE-2022-21699 are fixed in Python-ipython 7.16.3Windows
Vulnerabilities CVE-2022-21699 are fixed in Python-ipython 7.31.1Windows
Vulnerabilities CVE-2022-21699 are fixed in Python-ipython 8.0.1Windows
ipython security update(DSA-5065-1) ipython_5.8.0-1+deb10u1_all.debLinux
Enhanced interactive Python 3 shell (USN-5953-1) ipython_5.5.0-1_all.debLinux
Enhanced interactive Python 3 shell (USN-5953-1) ipython3_5.5.0-1_all.debLinux
Enhanced interactive Python 3 shell (USN-5953-1) ipython3_7.13.0-1_all.debLinux
Enhanced interactive Python 3 shell (USN-5953-1) python-ipython_5.5.0-1_all.debLinux
Enhanced interactive Python 3 shell (USN-5953-1) python3-ipython_5.5.0-1_all.debLinux
Enhanced interactive Python 3 shell (USN-5953-1) python3-ipython_7.13.0-1_all.debLinux
Vulnerabilities CVE-2022-21699 are fixed in Python-ipython for linux 5.11Linux
Vulnerabilities CVE-2022-21699 are fixed in Python-ipython for linux 7.16.3Linux
Vulnerabilities CVE-2022-21699 are fixed in Python-ipython for linux 7.31.1Linux
Vulnerabilities CVE-2022-21699 are fixed in Python-ipython for linux 8.0.1Linux
CVE-2022-21699NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234