Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-6345

Опубликовано: 15 июл. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.8

Описание

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

РелизСтатусПримечание
devel

not-affected

24.2+dfsg-1
esm-apps-legacy/xenial

released

8.1.1-2ubuntu0.6+esm8
esm-apps/bionic

released

9.0.1-2.3~ubuntu1.18.04.8+esm4
esm-apps/focal

released

20.0.2-5ubuntu1.10+esm2
esm-apps/jammy

not-affected

esm-apps/noble

not-affected

esm-apps/resolute

not-affected

24.2+dfsg-1
esm-apps/xenial

released

8.1.1-2ubuntu0.6+esm8
esm-infra-legacy/trusty

released

1.5.4-1ubuntu4+esm5
focal

ignored

end of standard support, was needed

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

released

44.0.0-2ubuntu0.1+esm1
esm-apps/jammy

released

44.1.1-1.2ubuntu0.22.04.1+esm1
esm-infra-legacy/trusty

released

3.3-1ubuntu2+esm2
esm-infra-legacy/xenial

released

20.7.0-1ubuntu0.1~esm2
esm-infra/bionic

released

39.0.1-2ubuntu0.1+esm1
esm-infra/xenial

released

20.7.0-1ubuntu0.1~esm2
focal

ignored

end of standard support, was needed
jammy

needed

noble

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

74.1.2-1
esm-infra/focal

released

45.2.0-1ubuntu0.2
focal

released

45.2.0-1ubuntu0.2
jammy

released

59.6.0-1.2ubuntu0.22.04.2
noble

released

68.1.2-2ubuntu1.1
oracular

not-affected

74.1.2-1
plucky

not-affected

74.1.2-1
questing

not-affected

74.1.2-1
resolute

not-affected

74.1.2-1
upstream

released

70.3.0-2

Показывать по

EPSS

Процентиль: 78%
0.01939
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
около 2 лет назад

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
nvd
около 2 лет назад

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
msrc
почти 2 года назад

Описание отсутствует

CVSS3: 8.8
debian
около 2 лет назад

A vulnerability in the package_index module of pypa/setuptools version ...

suse-cvrf
почти 2 года назад

Security update for python-setuptools

EPSS

Процентиль: 78%
0.01939
Низкий

8.8 High

CVSS3