python system_error ai_generated true

setuptools <70.0.0 存在 CVE-2024-6345 漏洞:package_index 下载函数允许通过构造的包 URL 执行远程代码。

setuptools <70.0.0 is vulnerable to CVE-2024-6345: package_index download functions allow remote code execution via crafted package URLs.

ID: python/setuptools-cve-2024-6345-remote-code

其他格式: JSON · Markdown 中文 · English
80%修复率
89%置信度
0证据数
2024-07-15首次发现

版本兼容性

版本状态引入弃用备注
3.8 active — — —
3.9 active — — —
3.10 active — — —
3.11 active — — —
3.12 active — — —

根因分析

setuptools 的 package_index 模块对不受信任的下载 URL 使用 `eval()`,从恶意索引安装时可导致远程代码执行。

English

setuptools' package_index module uses `eval()` on untrusted download URLs, enabling RCE when installing from a malicious index.

generic

解决方案

  1. 98% 成功率
    pip install --upgrade 'setuptools>=70.0.0'
  2. 90% 成功率
    pip install pip-audit && pip-audit

无效尝试

常见但无效的做法:

  1. 95% 失败

    Keeps the vulnerable version in place and exposes the environment to RCE.

  2. 70% 失败

    HTTPS does not protect against a malicious index that serves crafted URLs.

  3. 98% 失败

    Caching is unrelated to the vulnerability.