CVE-2023-6507
Groups not dropped before running subprocess when using empty 'extra_groups' parameter
描述
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed in CPython 3.12.1 and does not affect other stable releases. When using the `extra_groups=` parameter with an empty list as a value (ie `extra_groups=[]`) the logic regressed to not call `setgroups(0, NULL)` before calling `exec()`, thus not dropping the original processes' groups before starting the new process. There is no issue when the parameter isn't used or when any value is used besides an empty list. This issue only impacts CPython processes run with sufficient privilege to make the `setgroups` system call (typically `root`).
如何修補 CVE-2023-6507
要修補 CVE-2023-6507,請將受影響套件升級到下列已修補版本。
- —升級至 3.12.1 或更新版本
- —升級至 3.12.1 或更新版本
- —升級至 3.12.1 或更新版本
CVE-2023-6507 正在被利用嗎?
低 — EPSS 為 1.3%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- >= 3.12.0, < 3.12.1
- >= 3.12.0, < 3.12.1
- >= 3.12.0, < 3.12.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.9 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |