CVE-2022-39286

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-39286
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39286.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-39286
Aliases
Related
Published
2022-10-26T20:15:10Z
Modified
2025-01-15T02:34:33.307526Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in jupyter_core that stems from jupyter_core executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.

References

Affected packages

Debian:11 / jupyter-core

Package

Name
jupyter-core
Purl
pkg:deb/debian/jupyter-core?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.7.1-1+deb11u1

Affected versions

4.*

4.7.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / jupyter-core

Package

Name
jupyter-core
Purl
pkg:deb/debian/jupyter-core?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.11.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / jupyter-core

Package

Name
jupyter-core
Purl
pkg:deb/debian/jupyter-core?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.11.2-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/jupyter/jupyter_core

Affected ranges

Type
GIT
Repo
https://github.com/jupyter/jupyter_core
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

4.*

4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.1.0
4.1.1
4.10.0
4.11.0
4.11.1
4.2.0
4.2.1
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.6.2
4.6.3
4.7.0
4.7.0rc0
4.7.1
4.8.0
4.8.2
4.9.0
4.9.0rc0
4.9.1
4.9.1rc0
4.9.2