CVE-2022-39286
published 2022-10-26CVE-2022-39286: Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution…
PriorityP353high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.06%
60.6th percentile
Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | jupyter-core | < jupyter-core 4.11.2-1 (bookworm) | jupyter-core 4.11.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jupyter | jupyter_core | < 4.11.2 | 4.11.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Execution with Unnecessary Privileges in JupyterApp
osv·2022-10-26
CVE-2022-39286 [HIGH] Execution with Unnecessary Privileges in JupyterApp
Execution with Unnecessary Privileges in JupyterApp
### Impact
_What kind of vulnerability is it? Who is impacted?_
We’d like to disclose an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in the current working directory. This vulnerability allows one user to run code as another.
### Patches
_Has the problem been patched? What versions should users upgrade to?_
Users should upgrade to `jupyter_core>=4.11.2`.
### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
No
### References
_Are there any links users can visit to find out more?_
Similar advisory in [IPython](https://github.com/advisories/GHSA-pq7m-3gw7-gq5x)
GHSA
Execution with Unnecessary Privileges in JupyterApp
ghsa·2022-10-26
CVE-2022-39286 [HIGH] CWE-250 Execution with Unnecessary Privileges in JupyterApp
Execution with Unnecessary Privileges in JupyterApp
### Impact
_What kind of vulnerability is it? Who is impacted?_
We’d like to disclose an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in the current working directory. This vulnerability allows one user to run code as another.
### Patches
_Has the problem been patched? What versions should users upgrade to?_
Users should upgrade to `jupyter_core>=4.11.2`.
### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
No
### References
_Are there any links users can visit to find out more?_
Similar advisory in [IPython](https://github.com/advisories/GHSA-pq7m-3gw7-gq5x)
OSV
CVE-2022-39286: Jupyter Core is a package for the core common functionality of Jupyter projects
osv·2022-10-26·CVSS 8.8
CVE-2022-39286 [HIGH] CVE-2022-39286: Jupyter Core is a package for the core common functionality of Jupyter projects
Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.
Ubuntu
Jupyter Core vulnerability
vendor_ubuntu·2023-06-12
CVE-2022-39286 Jupyter Core vulnerability
Title: Jupyter Core vulnerability
Summary: Jupyter Core could be made to run programs as your login if it opened a
specially crafted file.
It was discovered that Jupyter Core executed untrusted files in the current
working directory. An attacker could possibly use this issue to execute
arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-39286: jupyter-core - Jupyter Core is a package for the core common functionality of Jupyter projects....
vendor_debian·2022·CVSS 8.8
CVE-2022-39286 [HIGH] CVE-2022-39286: jupyter-core - Jupyter Core is a package for the core common functionality of Jupyter projects....
Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.
Scope: local
bookworm: resolved (fixed in 4.11.2-1)
bullseye: resolved (fixed in 4.7.1-1+deb11u1)
forky: resolved (fixed in 4.11.2-1)
sid: resolved (fixed in 4.11.2-1)
trixie: resolved (fixed in 4.11.2-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/jupyter/jupyter_core/commit/1118c8ce01800cb689d51f655f5ccef19516e283https://github.com/jupyter/jupyter_core/security/advisories/GHSA-m678-f26j-3hrphttps://lists.debian.org/debian-lts-announce/2022/11/msg00022.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KKMP5OXXIX2QAUNVNJZ5UEQFKDYYJVBA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YIDN7JMLK6AOMBQI4QPSW4MBQGWQ5NIN/https://security.gentoo.org/glsa/202301-04https://www.debian.org/security/2023/dsa-5422https://github.com/jupyter/jupyter_core/commit/1118c8ce01800cb689d51f655f5ccef19516e283https://github.com/jupyter/jupyter_core/security/advisories/GHSA-m678-f26j-3hrphttps://lists.debian.org/debian-lts-announce/2022/11/msg00022.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KKMP5OXXIX2QAUNVNJZ5UEQFKDYYJVBA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YIDN7JMLK6AOMBQI4QPSW4MBQGWQ5NIN/https://security.gentoo.org/glsa/202301-04https://www.debian.org/security/2023/dsa-5422
2022-10-26
Published