easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.
CVSS Details
- CVSS 3.1 Base Score: 5.6
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-python/setuptools. | Oct 30, 2017 | Aug 5, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 2, 2013 |
| Suse | — | Upgrade sle-sdk-releaseUpgrade python-setuptools | May 29, 2014 | Aug 5, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub