CVE-2022-21699

HIGH

IPython - Code Injection

Title source: llm
STIX 2.1

Description

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

Scores

CVSS v3 8.2
EPSS 0.0150
EPSS Percentile 81.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-269 CWE-250 CWE-279
Status published
Products (7)
debian/debian_linux 9.0
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 34
fedoraproject/fedora 35
ipython/ipython < 5.10.0
pypi/ipython 0 - 5.11PyPI
Published Jan 19, 2022
Tracked Since Feb 18, 2026