EXPOSURES › CVE-2021-42952
CVE-2021-42952
CRITICAL
DETAIL
SourceNVD · cve
Published2022-02-25
CVSS9.9
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-42952 ↗
⚡ RCE
SHAME 50/100
rce
Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata
▸ RECOMMENDED ACTION Remote code execution — patch the affected products on priority.
PLAYERS IMPLICATED
DESCRIPTION
Zepl Notebooks before 2021-10-25 are affected by a sandbox escape vulnerability. Upon launching Remote Code Execution from the Notebook, users can then use that to subsequently escape the running context sandbox and proceed to access internal Zepl assets including cloud metadata services.
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.