Improper Link Resolution Before File Access ('Link Following') Affecting python package, versions [3.8.0,3.8.19) [3.9.0,3.9.19) [3.10.0,3.10.14) [3.11.0,3.11.9) [3.12.0,3.12.3)
Threat Intelligence
EPSS
0.05% (16th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UNMANAGED-PYTHON-7924822
- published 9 Sep 2024
- disclosed 19 Mar 2024
- credit Unknown
Introduced: 19 Mar 2024
CVE-2023-6597 Open this link in a new tabHow to fix?
Upgrade python
to version 3.8.19, 3.9.19, 3.10.14, 3.11.9, 3.12.3 or higher.
Overview
Affected versions of this package are vulnerable to Improper Link Resolution Before File Access ('Link Following') via the tempfile.TemporaryDirectory
class. An attacker can modify the permissions of files referenced by symlinks in some circumstances when privileged programs are run. This is only exploitable if the attacker has the ability to run privileged programs.
CVSS Scores
version 3.1