CVE-2024-47532
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
30/09/2024
Last modified:
15/11/2024
Description
RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application does not require access to the module string, it can remove it from RestrictedPython.Utilities.utility_builtins or otherwise do not make it available in the restricted execution environment.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zope:restrictedpython:*:*:*:*:*:*:*:* | 7.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



