python
system_error
ai_generated
true
setuptools <70.0.0 is vulnerable to CVE-2024-6345: package_index download functions allow remote code execution via crafted package URLs.
ID: python/setuptools-cve-2024-6345-remote-code
80%Fix Rate
89%Confidence
0Evidence
2024-07-15First Seen
Version Compatibility
| Version | Status | Introduced | Deprecated | Notes |
|---|---|---|---|---|
| 3.8 | active | — | — | — |
| 3.9 | active | — | — | — |
| 3.10 | active | — | — | — |
| 3.11 | active | — | — | — |
| 3.12 | active | — | — | — |
Root Cause
setuptools' package_index module uses `eval()` on untrusted download URLs, enabling RCE when installing from a malicious index.
generic中文
setuptools 的 package_index 模块对不受信任的下载 URL 使用 `eval()`,从恶意索引安装时可导致远程代码执行。
Workarounds
-
98% success
pip install --upgrade 'setuptools>=70.0.0'
-
90% success
pip install pip-audit && pip-audit
Dead Ends
Common approaches that don't work:
-
95% fail
Keeps the vulnerable version in place and exposes the environment to RCE.
-
70% fail
HTTPS does not protect against a malicious index that serves crafted URLs.
-
98% fail
Caching is unrelated to the vulnerability.