PT-2022-6759 · Unknown+5 · Jupyter Core+5
Published
2022-10-26
·
Updated
2025-10-20
·
CVE-2022-39286
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Jupyter Core versions prior to 4.11.2
Description
The issue is related to arbitrary code execution in
jupyter core due to the execution of untrusted files in the current working directory. This allows one user to run code as another, potentially leading to the disclosure of protected information and the upload and execution of code with elevated privileges.Recommendations
To resolve the issue, upgrade to Jupyter Core version 4.11.2 or later.
As a temporary workaround, consider restricting access to the
jupyter core functionality until a patch is applied.
Avoid executing untrusted files in the current working directory to minimize the risk of exploitation.Exploit
Fix
Improper Privilege Management
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Jupyter Core
Linuxmint
Red Os
Ubuntu