CVE Feed

    Dashboard / CVE / CVE-2024-47532

    CVE-2024-47532

    RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application does not require access to the module string, it can remove it from RestrictedPython.Utilities.utility_builtins or otherwise do not make it available in the restricted execution environment.

    Published:Sep 30, 2024
    Last Modified:Nov 15, 2024
    EPS:Sep 30, 2024
    EPSS Score:0.00779
    CVSS Score:6.5

    Affected Products

    Vendor
    Zope
    Product
    Restrictedpython

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High