easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.
oryginał ENCVSS Vector
AV:N/AC:M/Au:N/C:P/I:P/A:PPython Setuptools
APPPython0.6.400.6.410.6.420.6.430.6.440.6.450.6.460.6.470.6.480.6.49≤ 0.7b4
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
CWE
Powiązane podatności
CVE-2025-47273HIGH7.7ten sam produkt
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages....
CVE-2026-59890MEDIUM6.1ten sam produkt
setuptools to pakiet umożliwiający pobieranie, budowanie, instalowanie, uaktualnianie i odinstalowywanie pakie...
CVE-2022-40897MEDIUM5.9ten sam produkt
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of servic...
CVE-2022-48565CRITICAL9.8PL ✓ten sam vendor
XXE w module plistlib języka Python — wykonanie ataku na dane XML
CVE-2022-37454CRITICAL9.8PL ✓ten sam vendor
Integer overflow w implementacji SHA-3 (XKCP) umożliwiający RCE