CVE-2024-47532

RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application does not require access to the module string, it can remove it from RestrictedPython.Utilities.utility_builtins or otherwise do not make it available in the restricted execution environment.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zope:restrictedpython:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-30 16:15

Updated : 2024-11-15 17:59


NVD link : CVE-2024-47532

Mitre link : CVE-2024-47532

CVE.ORG link : CVE-2024-47532


JSON object : View

Products Affected

zope

  • restrictedpython
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo