Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-jupyter-core | Nov 18, 2022 | Oct 26, 2022 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-python-jupyter_core | Jan 12, 2023 | Oct 26, 2022 | |
| Ubuntu | ubuntu-pro-upgrade-python-jupyter-coreubuntu-pro-upgrade-python3-jupyter-coreubuntu-upgrade-python3-jupyter-core | Jun 12, 2023 | Oct 26, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub