GHSA-xjw2-6jm9-rf67

    Dashboard / Vulnerabilities / GHSA-xjw2-6jm9-rf67

    GHSA-xjw2-6jm9-rf67

    Published: 30 Aug 2023Last Modified: 16 Feb 2024

    Summary: Sandbox escape via various forms of "format".

    Details: ### Impact Python's "format" functionality allows someone controlling the format string to "read" all objects accessible through recursive attribute lookup and subscription from objects he can access. This can lead to critical information disclosure. With `RestrictedPython`, the format functionality is available via the `format` and `format_map` methods of `str` (and `unicode`) (accessed either via the class or its instances) and via `string.Formatter`. All known versions of `RestrictedPython` are vulnerable. ### Patches The issue will be fixed in 5.4 and 6.2. ### Workarounds There are no workarounds to fix the issue without upgrading. ### References * https://docs.python.org/3/library/stdtypes.html#str.format_map * http://lucumr.pocoo.org/2016/12/29/careful-with-str-format/ * https://www.exploit-db.com/exploits/51580 ### For more information If you have any questions or comments about this advisory: * Open an issue in the [RestrictedPython issue tracker](https://github.com/zopefoundation/RestrictedPython/issues) * Email us at [[email protected]](mailto:[email protected]) ### Credits Thanks for analysing and reporting the go to: * Abhishek Govindarasu * Ankush Menat * Ward Theunisse

    Affected packages

    Package

    Name: restrictedpython

    Purl: pkg:pypi/restrictedpython

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -5.4

    Affected versions

    3.4.2
    3.4.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-xjw2-6jm9-rf67 | CVE-DB