python system_error ai_generated true

setuptools <70.0.0 is vulnerable to CVE-2024-6345: package_index download functions allow remote code execution via crafted package URLs.

ID: python/setuptools-cve-2024-6345-remote-code

Also available as: JSON · Markdown · 中文
80%Fix Rate
89%Confidence
0Evidence
2024-07-15First Seen

Version Compatibility

VersionStatusIntroducedDeprecatedNotes
3.8 active — — —
3.9 active — — —
3.10 active — — —
3.11 active — — —
3.12 active — — —

Root Cause

setuptools' package_index module uses `eval()` on untrusted download URLs, enabling RCE when installing from a malicious index.

generic

中文

setuptools 的 package_index 模块对不受信任的下载 URL 使用 `eval()`,从恶意索引安装时可导致远程代码执行。

Workarounds

  1. 98% success
    pip install --upgrade 'setuptools>=70.0.0'
  2. 90% success
    pip install pip-audit && pip-audit

Dead Ends

Common approaches that don't work:

  1. 95% fail

    Keeps the vulnerable version in place and exposes the environment to RCE.

  2. 70% fail

    HTTPS does not protect against a malicious index that serves crafted URLs.

  3. 98% fail

    Caching is unrelated to the vulnerability.