Logo
vulnerabilityCVE-2024-6345
Name
CVE-2024-6345
Source
NVD ( link)Debian ( link)
Description
A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
python3-setuptools
Not Affected

Vulnerability Ratings#


8.8
other
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
80.9.0
Not Affected
buildroot
master
80.9.0
Not Affected
openwrt
master
82.0.1-r2
Not Affected
openwrt
openwrt-25.12
80.9.0-r3
Not Affected
yocto
kirkstone
59.5.0
Patched
yocto
scarthgap
69.1.1
Patched

Resolved with patches#


python3-setuptools (yocto:kirkstone)

#
Title
Author
Resolve
1
Merge pull request #4332 from pypa/debt/package-index-vcs
Jason R. Coombs <jaraco@jaraco.com>
CVE-2024-6345

python3-setuptools (yocto:scarthgap)

#
Title
Author
Resolve
1
Merge pull request #4332 from pypa/debt/package-index-vcs
Jason R. Coombs <jaraco@jaraco.com>
CVE-2024-6345