Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata services.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
http://zepl.com | |
https://seclists.org/fulldisclosure/2022/Feb/32 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-02-25T19:43:22
Updated: 2024-08-04T03:47:12.629Z
Reserved: 2021-10-25T00:00:00
Link: CVE-2021-42952
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-02-25T20:15:08.210
Modified: 2024-11-21T06:28:19.717
Link: CVE-2021-42952
Redhat
No data.