Skip to content
COOEY

EXPOSURES › CVE-2021-42952

CVE-2021-42952

CRITICAL
DETAIL
SourceNVD · cve Published2022-02-25 CVSS9.9 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-42952 ↗
⚡ RCE SHAME 50/100 rce

Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata services.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.