« Volver al listado

CVE-2024-6923

Estado: AplazadaMedia (5.5)—

There is a MEDIUM severity vulnerability affecting CPython.

The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-6923",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-6923",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-01T18:15:02.857863Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.1
      }
    ]
  },
  "affected": [
    {
      "source": "cna@python.org",
      "affectedData": [
        {
          "vendor": "Python Software Foundation",
          "modules": [
            "email"
          ],
          "product": "CPython",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.8.20",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.9.0",
              "lessThan": "3.9.20",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.10.0",
              "lessThan": "3.10.15",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.11.0",
              "lessThan": "3.11.10",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.12.0",
              "lessThan": "3.12.5",
              "versionType": "python"
            },
            {
              "status": "affected",
              "version": "3.13.0a1",
              "lessThan": "3.13.0rc2",
              "versionType": "python"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:python:cpython:*:*:*:*:*:*:*:*"
          ],
          "vendor": "python",
          "product": "cpython",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "python",
              "lessThanOrEqual": "3.13.0rc2"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-08-01T14:15:03.647",
  "references": [
    {
      "url": "https://github.com/python/cpython/commit/06f28dc236708f72871c64d4bc4b4ea144c50147",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/097633981879b3c9de9a1dd120d3aa585ecc2384",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/4766d1200fdf8b6728137aa2927a297e224d5fa7",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/4aaa4259b5a6e664b7316a4d60bdec7ee0f124d0",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/b158a76ce094897c870fb6b3de62887b7ccc33f1",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/f7be505d137a22528cb0fc004422c0081d5d90e6",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/commit/f7c0f09e69e950cf3c5ada9dbde93898eb975533",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/issues/121650",
      "source": "cna@python.org"
    },
    {
      "url": "https://github.com/python/cpython/pull/122233",
      "source": "cna@python.org"
    },
    {
      "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/QH3BUOE2DYQBWP7NAQ7UNHPPOELKISRW/",
      "source": "cna@python.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/08/01/3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2024/08/02/2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00005.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240926-0003/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "There is a MEDIUM severity vulnerability affecting CPython.\n\nThe \nemail module didn’t properly quote newlines for email headers when \nserializing an email message allowing for header injection when an email\n is serialized."
    },
    {
      "lang": "es",
      "value": "Existe una vulnerabilidad de gravedad MEDIA que afecta a CPython. El módulo de correo electrónico no citaba correctamente las nuevas líneas para los encabezados de correo electrónico al serializar un mensaje de correo electrónico, lo que permitía la inyección de encabezado cuando se serializa un correo electrónico."
    }
  ],
  "lastModified": "2026-06-17T08:18:59.170",
  "sourceIdentifier": "cna@python.org"
}