Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata services.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-29907 | Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata services. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| http://zepl.com |
|
| https://seclists.org/fulldisclosure/2022/Feb/32 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:47:12.629Z
Reserved: 2021-10-25T00:00:00
Link: CVE-2021-42952
No data.
Status : Modified
Published: 2022-02-25T20:15:08.210
Modified: 2024-11-21T06:28:19.717
Link: CVE-2021-42952
No data.
OpenCVE Enrichment
No data.
EUVD