CVE-2022-39286

Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
GitHub_MCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
VendorProductVersion
jupyterjupyter_core
𝑥
< 4.11.2
debiandebian_linux
10.0
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jupyter-core
bullseye (security)
4.7.1-1+deb11u1
fixed
bullseye
4.7.1-1+deb11u1
fixed
bookworm
4.12.0-1
fixed
sid
5.7.2-4
fixed
trixie
5.7.2-4
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jupyter-core
lunar
not-affected
kinetic
Fixed 4.11.1-1ubuntu0.22.10.1
released
jammy
Fixed 4.9.1-1ubuntu0.1~esm1
released
focal
Fixed 4.6.3-3ubuntu0.1~esm1
released
bionic
Fixed 4.4.0-2ubuntu0.1~esm1
released
xenial
ignored
trusty
ignored