Vulnerability · NVD
CVE-2023-38898
CVE-2023-38898, medium severity (CVSS 5.3): 3 tracked apps concerned, all fixed or indeterminable on their current version.
- Severity (CVSS)
- 5.3
- Exploitation
- 1.7 %
- Tracked apps
- 3
- Still exposed
- 0
NVD scale
EPSS, predicted over 30 days
An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases); (2) there are no common scenarios in which an adversary can call _asyncio._swap_current_task but does not already have the ability to call arbitrary functions; and (3) there are no common scenarios in which sensitive information, which is not already accessible to an adversary, becomes accessible through this bug.
Show raw CVSS vector
Tracked apps referencing this CVE
For each app: the affected range, the fixing version, and where the tracked app stands today.
Vulnerable CPE configurations (1)
| Vendor | Product | Platform | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| python |
python All platforms (wildcard)
|
All platforms (wildcard) | - | cpe:2.3:a:python:python:3.13.0:alpha0:*:*:*:*:*:* |
Manage your fleet with Appaloosa
Appaloosa pushes OS updates, apps and policies to your Windows, macOS, iOS and Android devices from one console.