cbcvebase.
CVE-2022-21699
published 2022-01-19

CVE-2022-21699: IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming…

PriorityP348high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.66%
47.4th percentile
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianipython< ipython 7.31.1-1 (bookworm)ipython 7.31.1-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
ipythonipython< 5.115.11
ipythonipython<= 5.10.0
ipythonipython
ipythonipython
ipythonipython
ipythonipython>= 0 < 7.20.0-1+deb11u17.20.0-1+deb11u1
ipythonipython>= 0 < 7.31.1-17.31.1-1
ipythonipython>= 0 < 7.31.1-17.31.1-1
ipythonipython>= 0 < 7.31.1-17.31.1-1
ipythonipython>= 0 < 5.115.11
ipythonipython>= 0 < 1.2.1-2ubuntu0.1~esm11.2.1-2ubuntu0.1~esm1
ipythonipython>= 0 < 5.5.0-1ubuntu0.1~esm15.5.0-1ubuntu0.1~esm1
ipythonipython>= 0 < 7.13.0-1ubuntu0.1~esm17.13.0-1ubuntu0.1~esm1
ipythonipython>= 6.0.0 < 7.16.37.16.3
ipythonipython>= 6.0.0 < 7.16.37.16.3
ipythonipython>= 7.17.0 < 7.31.17.31.1
ipythonipython>= 7.17.0 < 7.31.17.31.1
ipythonipython>= 8.0.0 < 8.0.18.0.1
ipythonipython>= 8.0.0 < 8.0.18.0.1

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.