Critical
Low
Medium

CVE-2024-6345 — PyPA Setuptools Code Injection

Overview

Critical
Low
Medium
No items found.

Package: setuptools

Impact: Code injection via malicious package URLs

Fix: Update to setuptools v70.0+

Year: 2024

CVSS:

Severity: High

Affected Components

Location

* setuptools/package_index.py 

* def download(self, spec, tmpdir):

Stop the waste.
Protect your environment with Kodem.

Get a personalized demo
Get a personalized demo