[WID-SEC-2024-1756] Red Hat Enterprise Linux (python-setuptools): Schwachstelle ermöglicht Codeausführung CVSS Base Score 8.8 (hoch) CVSS Temporal Score 7.7 (hoch) Remoteangriff ja Datum 04.08.2024 Stand UPDATE 30.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Produktbeschreibung Red Hat Enterprise Linux (RHEL) ist eine populäre Linux-Distribution. Produkte UPDATE 16.10.2025 NetApp ActiveIQ Unified Manager UPDATE 01.10.2025 Dell PowerProtect Data Domain <8.4.0.0 Dell PowerProtect Data Domain <7.10.1.70 Dell PowerProtect Data Domain <7.13.1.40 Dell PowerProtect Data Domain <8.3.1.10 UPDATE 07.07.2025 Splunk Splunk Enterprise <9.4.3 Splunk Splunk Enterprise <9.3.5 Splunk Splunk Enterprise <9.2.7 Splunk Splunk Enterprise <9.1.10 UPDATE 02.06.2025 Xerox FreeFlow Print Server 9 UPDATE 17.03.2025 IBM QRadar SIEM 7.5.0 UPDATE 16.03.2025 IBM App Connect Enterprise Certified Container Operator <12.8.2 IBM App Connect Enterprise Certified Container Operator <12.0.8 UPDATE 17.12.2024 IBM Sterling Connect:Direct <6.3.0.11_ifix001 UPDATE 18.09.2024 Amazon Linux 2 UPDATE 17.09.2024 IBM QRadar SIEM <7.5.0 UP9 IF03 UPDATE 10.09.2024 IBM InfoSphere Information Server 11.7 UPDATE 02.09.2024 SUSE Linux UPDATE 21.08.2024 RESF Rocky Linux UPDATE 14.08.2024 Oracle Linux UPDATE 12.08.2024 Splunk Splunk Enterprise UPDATE 06.08.2024 Red Hat Enterprise Linux 04.08.2024 Red Hat Enterprise Linux 8.8 Red Hat Enterprise Linux python-setuptools <69.1.1 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um beliebigen Programmcode auszuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A critical vulnerability (CVSS 8.8) in the python-setuptools package for Red Hat Enterprise Linux allows a remote, anonymous attacker to execute arbitrary code. The specific affected version is python-setuptools prior to version 69.1.1 on RHEL 8.8, and the flaw also impacts a wide range of other enterprise products including specific versions of Splunk Enterprise, Dell PowerProtect Data Domain, IBM QRadar SIEM, and several other Linux distributions. Mitigations are available, and users should apply the relevant vendor patches.