Back

HIGH

Remote Code Execution in pypa/setuptools

Published Jul 15, 2024

Description

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

Affected products

Remediation

Red Hat statement

Red Hat OpenStack does not include setuptools. The ImcSdk component uses it only during compile time in our build systems, and we do not support recompiling SRPMs. As a result, Red Hat OpenStack is not affected by this flaw. Python 2.7.18 was marked End of Life on 04/20/2020. No patches for Python 2 would be made available.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Jul 15, 2024
Updated Nov 4, 2025
Reserved Jun 26, 2024
CISA Vulnrichment
Updated Jul 15, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 15, 2024
GHSA-CX63-2MW6-8HW5