CVE-2023-41050
Information disclosure in AccessControl
描述
### Impact Python's "format" functionality allows someone controlling the format string to "read" objects accessible (recursively) via attribute access and subscription from accessible objects. Those attribute accesses and subscriptions use Python's full blown `getattr` and `getitem`, not the policy restricted `AccessControl` variants `_getattr_` and `_getitem_`. This can lead to critical information disclosure. `AccessControl` already provides a safe variant for `str.format` and denies access to `string.Formatter`. However, `str.format_map` is still unsafe. Affected are all users who allow untrusted users to create `AccessControl` controlled Python code and execute it. ### Patches A fix will be introduced in the versions 4.4, 5.8 and 6.2. ### Workarounds There are no workarounds. ### References https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-xjw2-6jm9-rf67 describes the corresponding problem for `RestrictedPython`.
如何修補 CVE-2023-41050
要修補 CVE-2023-41050,請將受影響套件升級到下列已修補版本。
- —升級至 4.4 或更新版本
- —升級至 4.4 或更新版本
- —升級至 4.8.9 或更新版本
- —升級至 4.8.9 或更新版本
CVE-2023-41050 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 4.4
- from 0, < 4.4, >= 5.0, < 5.8, >= 6.0, < 6.2
- from 0, < 4.8.9
- from 0, < 4.8.9, >= 5.0.0, < 5.8.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.8 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |