-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerability with setuptools < 70.0.0 (CVE-2024-6345) #942
Comments
Not that this only affects version 3.11 and under. Version 3.12 is not affected. |
Could this also be fixed in the 3.10 images? Thank you |
@LaurentGoderre Is it alright if we make the same change as in PR #783, specifically updating the |
Current versions of 3.11.9: 65.5.1
3.10.14: 65.5.1
3.9.19: 58.1.0
3.8.19: 57.5.0 Do we have any idea how many breaking changes there are between even 65.5.1 and 70.0.0? Also, any idea whether cpython upstream plans to do a new release with a different version bundled, since their upstream artifacts are also affected? |
I'll also link to #781 (comment) explicitly, as it's even more relevant here (where the proposed update is 65.5.1 -> 70.0.0, not just 65.5.0 -> 65.5.1 as it was there). |
I think I'm understanding correctly that this is only a security issue if you're blindly trusting attacker-controlled URLs and asking for them to be installed? That seems to limit the spread/impact considerably, especially since |
pypa/setuptools@v65.5.1...v70.0.0 is frankly a huge amount of change, and I'm certainly not comfortable making the blanket decision that this aggressive of an update is "OK" for all users of these images. (Again, see #781 (comment) for a longer-form explanation of where I [still] stand on this.) |
This comment was marked as duplicate.
This comment was marked as duplicate.
This comment was marked as duplicate.
This comment was marked as duplicate.
if you don't need setuptools once your image is built, you may uninstall it (i.e. include |
Hello,
I've seen CVE-2024-6345 report today. I was wondering if you plan to update setuptools at least on 3.11 images like you did in the past on #783.
Thank you
The text was updated successfully, but these errors were encountered: