Aller au contenu
Appaloosa Scout

Vulnérabilité · NVD

CVE-2023-6507

MEDIUM 6.1

EN An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases.

When using the `extra_groups=` parameter with an empty list as a value (ie `extra_groups=[]`) the logic regressed to not call `setgroups(0, NULL)` before calling `exec()`, thus not dropping the original processes' groups before starting the new process. There is no issue when the parameter isn't used or when any value is used besides an empty list.

This issue only impacts CPython processes run with sufficient privilege to make the `setgroups` system call (typically `root`).

Vecteur d'attaque : Réseau adjacent Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
EPSS 1.33% au-dessus de la médiane percentile 68.3%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

  • Python 3.12 Windows winget:Python.Python.3.12
    Affecté Corrigé Dernière suivie 3.12.10 indéterminé
Configurations CPE vulnérables (3)
Vendor Produit Versions
python python
Toutes plateformes (wildcard)
python python
Toutes plateformes (wildcard)
python python
Toutes plateformes (wildcard)
Voir sur NVD ↗ Advisory · github.com