Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2023-38898

CVE-2023-38898, sévérité medium (CVSS 5.3) : 3 apps suivies concernées, toutes corrigées ou à statut indéterminable en version courante.

Gravité (CVSS)
5.3

Échelle NVD

Exploitation
1.7 %

EPSS, prédiction à 30 jours

Apps suivies
3
Encore exposées
0

EN An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases); (2) there are no common scenarios in which an adversary can call _asyncio._swap_current_task but does not already have the ability to call arbitrary functions; and (3) there are no common scenarios in which sensitive information, which is not already accessible to an adversary, becomes accessible through this bug.

Vecteur d'attaque : Réseau Aucun privilège requis Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS 1.74% au-dessus de la médiane percentile 76.4%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

  • Python 3.12 Windows winget:Python.Python.3.12
    Affecté - Corrigé - Dernière suivie 3.12.10 indéterminé
  • Python 3.13 Windows winget:Python.Python.3.13
    Affecté - Corrigé - Dernière suivie 3.13.15 indéterminé
  • Python 3.14 Windows winget:Python.Python.3.14
    Affecté - Corrigé - Dernière suivie 3.14.7 indéterminé
Configurations CPE vulnérables (1)
Vendor Produit Versions
python python
Toutes plateformes (wildcard)
-
Voir sur NVD ↗ Advisory · github.com