← Back to CVEs
CVE-2021-42950
HIGH8.8
Description
Remote Code Execution (RCE) vulnerability exists in Zepl Notebooks all previous versions before October 25 2021. Users can register for an account and are allocated a set number of credits to try the product. Once users authenticate, they can proceed to create a new organization by which additional users can be added for various collaboration abilities, which allows malicious user to create new Zepl Notebooks with various languages, contexts, and deployment scenarios. Upon creating a new notebook with specially crafted malicious code, a user can then launch remote code execution.
CVE Details
CVSS v3.1 Score8.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published3/3/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
zepl:zepl
References
http://zepl.com(cve@mitre.org)
https://seclists.org/fulldisclosure/2022/Feb/31(cve@mitre.org)
http://zepl.com(af854a3a-2127-422b-91ae-364da2661108)
https://seclists.org/fulldisclosure/2022/Feb/31(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.