Skip to content

Information leakage via `AttributeError.obj` and the `string` module

Moderate
d-maurer published GHSA-5rfv-66g4-jr8h Sep 30, 2024

Package

RestrictedPython

Affected versions

< 7.3

Patched versions

7.3

Description

Impact

A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module.

Patches

The problem will be fixed in version 7.3.

Workarounds

If the application does not require access to the module string, it can remove it from RestrictedPython.Utilities.utility_builtins or otherwise do not make it available in the restricted execution environment.

Severity

Moderate

CVE ID

CVE-2024-47532

Weaknesses

No CWEs

Credits