CVE-2022-21699

unknown
Published 2022-01-21 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVSS v2
VIR risk

Description

IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as another on the same machine. All users are advised to upgrade.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2022-21699

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2022-21699.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed7.31.1-1
debian debianbullseyefixed7.20.0-1+deb11u1
debian debianforkyfixed7.31.1-1
debian debiansidfixed7.31.1-1
debian debiantrixiefixed7.31.1-1

Package impact

EcosystemPackageVulnerableFixed
python PyPIipython<5.115.11
python PyPIipython>=6.0.0,<7.16.37.16.3
python PyPIipython>=7.17.0,<7.31.17.31.1
python PyPIipython>=8.0.0,<8.0.18.0.1
python PyPIipython<46a51ed69cdf41b4333943d9ceeb945c4ede5668||>=8.0.0,<8.0.146a51ed69cdf41b4333943d9ceeb945c4ede5668

References

Verify integrity in audit chain (admin only). AS-IS.