« Volver al listado

CVE-2023-6597

Estado: AplazadaAlta (7.8)—

An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.

The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6597",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-6597",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-05T19:08:44.665083Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cna@python.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 1.4
      }
    ]
  },
  "affected": [
    {
      "source": "cna@python.org",
      "affectedData": [
        {
          "repo": "https://github.com/python/cpython",
          "vendor": "Python Software Foundation",
          "product": "CPython",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.8.19",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.9.0",
              "lessThan": "3.9.19",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.10.0",
              "lessThan": "3.10.14",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.11.0",
              "lessThan": "3.11.8",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.12.0",
              "lessThan": "3.12.1",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.13.0a1",
              "lessThan": "3.13.0a3",
              "versionType": "python"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:python_software_foundation:cpython:*:*:*:*:*:*:*:*"
          ],
          "vendor": "python_software_foundation",
          "product": "cpython",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.8.19",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.9.0",
              "lessThan": "3.9.19",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.10.0",
              "lessThan": "3.10.14",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.11.0",
              "lessThan": "3.11.8",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.12.0",
              "lessThan": "3.12.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.13.0a1",
              "lessThan": "3.13.0a3",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-03-19T16:15:08.743",
  "references": [
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/03/20/5",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/02a9259c717738dfe6b463c44d7e17f2b6d2cb3a",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/5585334d772b253a01a6730e8202ffb1607c3d25",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/6ceb8aeda504b079fef7a57b8d81472f15cdd9a5",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/81c16cd94ec38d61aa478b9a452436dc3b1b524d",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/8eaeefe49d179ca4908d052745e3bb8b6f238f82",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/d54e22a669ae6e987199bb5d2c69bb5a46b0083b",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/issues/91133",
      "source": "cna@python.org"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00025.html",
      "source": "cna@python.org"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3IGRX54M7RNCQOXVQO5KQKTGWCOABIM/",
      "source": "cna@python.org"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5VHWS52HGD743C47UMCSAK2A773M2YE/",
      "source": "cna@python.org"
    },
    {
      "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/Q5C6ATFC67K53XFV4KE45325S7NS62LD/",
      "source": "cna@python.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/03/20/5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/python/cpython/commit/02a9259c717738dfe6b463c44d7e17f2b6d2cb3a",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/python/cpython/commit/5585334d772b253a01a6730e8202ffb1607c3d25",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/python/cpython/commit/6ceb8aeda504b079fef7a57b8d81472f15cdd9a5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/python/cpython/commit/81c16cd94ec38d61aa478b9a452436dc3b1b524d",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/python/cpython/commit/8eaeefe49d179ca4908d052745e3bb8b6f238f82",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/python/cpython/commit/d54e22a669ae6e987199bb5d2c69bb5a46b0083b",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/python/cpython/issues/91133",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00025.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00005.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T3IGRX54M7RNCQOXVQO5KQKTGWCOABIM/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5VHWS52HGD743C47UMCSAK2A773M2YE/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/Q5C6ATFC67K53XFV4KE45325S7NS62LD/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.\n\nThe tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.\n"
    },
    {
      "lang": "es",
      "value": "Se encontró un problema en la clase CPython `tempfile.TemporaryDirectory` que afecta a las versiones 3.12.2, 3.11.8, 3.10.13, 3.9.18 y 3.8.18 y anteriores. La clase tempfile.TemporaryDirectory eliminaría la referencia a enlaces simbólicos durante la limpieza de errores relacionados con permisos. Esto significa que los usuarios que pueden ejecutar programas privilegiados pueden modificar los permisos de los archivos a los que hacen referencia los enlaces simbólicos en algunas circunstancias."
    }
  ],
  "lastModified": "2026-06-17T06:51:03.620",
  "sourceIdentifier": "cna@python.org"
}