Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in jupyter_core
that stems from jupyter_core
executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this issue. There are no known workarounds.
The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jupyter_core | Jupyter | * | 4.11.2 (excluding) |
Jupyter-core | Ubuntu | bionic | * |
Jupyter-core | Ubuntu | esm-apps/bionic | * |
Jupyter-core | Ubuntu | esm-apps/focal | * |
Jupyter-core | Ubuntu | esm-apps/jammy | * |
Jupyter-core | Ubuntu | focal | * |
Jupyter-core | Ubuntu | jammy | * |
Jupyter-core | Ubuntu | kinetic | * |
Jupyter-core | Ubuntu | trusty | * |
Jupyter-core | Ubuntu | upstream | * |
Jupyter-core | Ubuntu | xenial | * |