Skip to content

Update bundled setuptools to address CVE-2024-6345, CVE-2022-40897 in cpython 3.9, 3.10 & 3.11 #131864

@briensea

Description

@briensea

Update bundled setuptools to address CVE-2024-6345, CVE-2022-40897 in cpython 3.9, 3.10 & 3.11

Description:

Security vulnerabilities, CVE-2024-6345 and CVE-2022-40897, have been identified in older versions of setuptools. The versions of setuptools bundled with CPython 3.9, 3.10, and 3.11 are affected.

This results in users being required to manually update setuptools to mitigate these security vulnerabilities.

CPython versions affected:

  • 3.9 (bundled setuptools version outdated)
  • 3.10 (bundled setuptools version outdated)
  • 3.11 (bundled setuptools version outdated)

Operating systems tested on:

  • Linux

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.10only security fixes3.11only security fixes3.9only security fixesstdlibStandard Library Python modules in the Lib/ directorytype-securityA security issue

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions