Metrics
Affected Vendors & Products
Thu, 12 Jun 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Debian
Debian debian Linux Python Python setuptools |
|
CPEs | cpe:2.3:a:python:setuptools:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
|
Vendors & Products |
Debian
Debian debian Linux Python Python setuptools |
|
Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 28 May 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Wed, 21 May 2025 03:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Mon, 19 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 17 May 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue. | |
Title | setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write | |
Weaknesses | CWE-22 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-17T15:46:11.399Z
Updated: 2025-05-28T15:03:15.516Z
Reserved: 2025-05-05T16:53:10.372Z
Link: CVE-2025-47273

Updated: 2025-05-28T15:03:15.516Z

Status : Analyzed
Published: 2025-05-17T16:15:19.110
Modified: 2025-06-12T16:29:01.660
Link: CVE-2025-47273
