# setuptools <70.0.0 存在 CVE-2024-6345 漏洞：package_index 下载函数允许通过构造的包 URL 执行远程代码。

- **ID:** `python/setuptools-cve-2024-6345-remote-code`
- **领域:** python
- **类别:** system_error
- **验证级别:** ai_generated
- **修复率:** 80%

## 根因

setuptools 的 package_index 模块对不受信任的下载 URL 使用 `eval()`，从恶意索引安装时可导致远程代码执行。

## 版本兼容性

| 版本 | 状态 | 引入 | 弃用 |
|------|------|------|------|
| 3.8 | active | — | — |
| 3.9 | active | — | — |
| 3.10 | active | — | — |
| 3.11 | active | — | — |
| 3.12 | active | — | — |

## 解决方案

1. **** (98% 成功率)
   ```
   pip install --upgrade 'setuptools>=70.0.0'
   ```
2. **** (90% 成功率)
   ```
   pip install pip-audit && pip-audit
   ```

## 无效尝试

- **** — Keeps the vulnerable version in place and exposes the environment to RCE. (95% 失败率)
- **** — HTTPS does not protect against a malicious index that serves crafted URLs. (70% 失败率)
- **** — Caching is unrelated to the vulnerability. (98% 失败率)
