python
system_error
ai_generated
true
setuptools <70.0.0 存在 CVE-2024-6345 漏洞:package_index 下载函数允许通过构造的包 URL 执行远程代码。
setuptools <70.0.0 is vulnerable to CVE-2024-6345: package_index download functions allow remote code execution via crafted package URLs.
ID: python/setuptools-cve-2024-6345-remote-code
80%修复率
89%置信度
0证据数
2024-07-15首次发现
版本兼容性
| 版本 | 状态 | 引入 | 弃用 | 备注 |
|---|---|---|---|---|
| 3.8 | active | — | — | — |
| 3.9 | active | — | — | — |
| 3.10 | active | — | — | — |
| 3.11 | active | — | — | — |
| 3.12 | active | — | — | — |
根因分析
setuptools 的 package_index 模块对不受信任的下载 URL 使用 `eval()`,从恶意索引安装时可导致远程代码执行。
English
setuptools' package_index module uses `eval()` on untrusted download URLs, enabling RCE when installing from a malicious index.
解决方案
-
98% 成功率
pip install --upgrade 'setuptools>=70.0.0'
-
90% 成功率
pip install pip-audit && pip-audit
无效尝试
常见但无效的做法:
-
95% 失败
Keeps the vulnerable version in place and exposes the environment to RCE.
-
70% 失败
HTTPS does not protect against a malicious index that serves crafted URLs.
-
98% 失败
Caching is unrelated to the vulnerability.