Ubuntu 18.04 ESM / 20.04 ESM : IPython vulnerabilities (USN-5953-1)
Discription

The remote Ubuntu 18.04 ESM / 20.04 ESM host has packages installed that are affected by multiple vulnerabilities as referenced in the USN-5953-1 advisory.

– Cross-site request forgery in the REST API in IPython 2 and 3. (CVE-2015-5607)

– IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade. (CVE-2022-21699)

Note that Nessus has not tested for these issues but has instead relied only on the application’s self-reported version number.Read More

6.8 Medium

CVSS2

  • Access Vector
  • Access Complexity
  • Authentication
  • Confidentiality Impact
  • Integrity Impact
  • Availability Impact
  • Network
  • Medium
  • None
  • Partial
  • Partial
  • Partial

8.8 High

CVSS3

  • Attack Vector
  • Attack Complexity
  • Privileges Required
  • User Interaction
  • Scope
  • Confidentiality Impact
  • Integrity Impact
  • Availability Impact
  • Network
  • Low
  • None
  • Required
  • Unchanged
  • High
  • High
  • High

Back to Main

Subscribe for the latest news: