CVE-2023-38898

An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases); (2) there are no common scenarios in which an adversary can call _asyncio._swap_current_task but does not already have the ability to call arbitrary functions; and (3) there are no common scenarios in which sensitive information, which is not already accessible to an adversary, becomes accessible through this bug.
References
Link Resource
https://github.com/python/cpython/issues/105987 Exploit Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:python:python:3.13.0:alpha0:*:*:*:*:*:*

History

21 Mar 2024, 02:48

Type Values Removed Values Added
Summary
  • (es) Un problema en Python cpython v.3.7 permite a un atacante obtener información sensible a través del componente _asyncio._swap_current_task. NOTA: esto es discutido por el vendedor porque (1) ni la versión 3.7 ni ninguna otra está afectada (es un fallo en algunas versiones previas a la 3.12); (2) no hay escenarios comunes en los que un adversario pueda llamar a _asyncio._swap_current_task pero no tenga ya la capacidad de llamar a funciones arbitrarias; y (3) no hay escenarios comunes en los que información sensible, que no esté ya accesible para un adversario, se vuelva accesible a través de este fallo.

07 Nov 2023, 04:17

Type Values Removed Values Added
Summary ** DISPUTED ** An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases); (2) there are no common scenarios in which an adversary can call _asyncio._swap_current_task but does not already have the ability to call arbitrary functions; and (3) there are no common scenarios in which sensitive information, which is not already accessible to an adversary, becomes accessible through this bug. An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases); (2) there are no common scenarios in which an adversary can call _asyncio._swap_current_task but does not already have the ability to call arbitrary functions; and (3) there are no common scenarios in which sensitive information, which is not already accessible to an adversary, becomes accessible through this bug.

25 Aug 2023, 01:15

Type Values Removed Values Added
Summary An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. ** DISPUTED ** An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the _asyncio._swap_current_task component. NOTE: this is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases); (2) there are no common scenarios in which an adversary can call _asyncio._swap_current_task but does not already have the ability to call arbitrary functions; and (3) there are no common scenarios in which sensitive information, which is not already accessible to an adversary, becomes accessible through this bug.

24 Aug 2023, 18:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.3

24 Aug 2023, 07:15

Type Values Removed Values Added
References
  • {'url': 'http://python.com', 'name': 'http://python.com', 'tags': ['Not Applicable'], 'refsource': 'MISC'}

22 Aug 2023, 15:07

Type Values Removed Values Added
CPE cpe:2.3:a:python:python:3.13.0:alpha0:*:*:*:*:*:*
CWE NVD-CWE-Other
First Time Python
Python python
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (MISC) https://github.com/python/cpython/issues/105987 - (MISC) https://github.com/python/cpython/issues/105987 - Exploit, Issue Tracking, Patch
References (MISC) http://python.com - (MISC) http://python.com - Not Applicable

15 Aug 2023, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-15 17:15

Updated : 2024-04-11 01:20


NVD link : CVE-2023-38898

Mitre link : CVE-2023-38898

CVE.ORG link : CVE-2023-38898


JSON object : View

Products Affected

python

  • python