Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-6345

Опубликовано: 15 июл. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.8

Описание

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

РелизСтатусПримечание
devel

not-affected

24.2+dfsg-1
esm-apps/bionic

released

9.0.1-2.3~ubuntu1.18.04.8+esm4
esm-apps/focal

released

20.0.2-5ubuntu1.10+esm2
esm-apps/jammy

not-affected

esm-apps/noble

not-affected

esm-apps/xenial

released

8.1.1-2ubuntu0.6+esm8
esm-infra-legacy/trusty

not-affected

1.5.4-1ubuntu4+esm5
focal

ignored

end of standard support, was needed
jammy

not-affected

22.0.2+dfsg-1ubuntu0.4
noble

not-affected

24.0+dfsg-1ubuntu1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

released

44.0.0-2ubuntu0.1+esm1
esm-apps/jammy

released

44.1.1-1.2ubuntu0.22.04.1+esm1
esm-infra-legacy/trusty

not-affected

3.3-1ubuntu2+esm2
esm-infra/bionic

released

39.0.1-2ubuntu0.1+esm1
esm-infra/xenial

released

20.7.0-1ubuntu0.1~esm2
focal

ignored

end of standard support, was needed
jammy

needed

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

74.1.2-1
esm-infra/focal

not-affected

45.2.0-1ubuntu0.2
focal

released

45.2.0-1ubuntu0.2
jammy

released

59.6.0-1.2ubuntu0.22.04.2
noble

released

68.1.2-2ubuntu1.1
oracular

not-affected

74.1.2-1
plucky

not-affected

74.1.2-1
upstream

released

70.3.0-2

Показывать по

EPSS

Процентиль: 45%
0.00227
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
около 1 года назад

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
nvd
около 1 года назад

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
msrc
10 месяцев назад

Описание отсутствует

CVSS3: 8.8
debian
около 1 года назад

A vulnerability in the package_index module of pypa/setuptools version ...

suse-cvrf
11 месяцев назад

Security update for python-setuptools

EPSS

Процентиль: 45%
0.00227
Низкий

8.8 High

CVSS3