Msrc Cbl2 Python3 3.9.19-1 On Cbl Mariner 2.0 vulnerabilities
5 known vulnerabilities affecting msrc/cbl2_python3_3.9.19-1_on_cbl_mariner_2.0.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-6597HIGHCVSS 7.82024-03-12
CVE-2023-6597 [HIGH] An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1 3.11.7 3.10.13 3.9.18 and 3.8.18 and prior.
The tempfile.TemporaryDirectory class would dereference sym
An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1 3.11.7 3.10.13 3.9.18 and 3.8.18 and prior.
The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can
msrc
CVE-2024-0450MEDIUMCVSS 6.22024-03-12
CVE-2024-0450 [MEDIUM] CWE-405 Quoted zip-bomb protection for zipfile
Quoted zip-bomb protection for zipfile
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft
msrc
CVE-2023-40217MEDIUMCVSS 5.32023-08-08
CVE-2023-40217 [MEDIUM] An issue was discovered in Python before 3.8.18 3.9.x before 3.9.18 3.10.x before 3.10.13 and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authenticati
An issue was discovered in Python before 3.8.18 3.9.x before 3.9.18 3.10.x before 3.10.13 and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created receives data into the socket bu
msrc
CVE-2022-42919HIGHCVSS 7.82022-11-08
CVE-2022-42919 [HIGH] Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library when used with the forkserver start me
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library when used with the forkserver start method on Linux allows pickles to be deserialized from any user in the same mac
msrc
CVE-2021-28861HIGHCVSS 7.42022-08-09
CVE-2021-28861 [HIGH] CWE-601 Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NO
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html do
msrc