Description
RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application does not require access to the module string, it can remove it from RestrictedPython.Utilities.utility_builtins or otherwise do not make it available in the restricted execution environment.
INFO
Published Date :
2024-09-30T15:29:57.907Z
Last Modified :
2024-09-30T17:29:29.522Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2024-47532 vulnerability.
| Vendors | Products |
|---|---|
| Zope |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-47532.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact