CVE-2020-15801: Critical severity python 2.7 vulnerability
In Python 3.8.4, sys.path restrictions specified in a python38.pth file are ignored, allowing code to be loaded from arbitrary locations. The <executable-name>.pth file (e.g., the python.pth file) is not affected.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-15801?
CVE-2020-15801 is a vulnerability in Python 3.8.4 that allows code to be loaded from arbitrary locations by ignoring sys.path restrictions specified in a python38._pth file.
What is the severity of CVE-2020-15801?
The severity of CVE-2020-15801 is critical with a CVSS score of 9.8.
How does CVE-2020-15801 affect Python?
CVE-2020-15801 affects Python versions 3.7.0 to 3.7.9 and 3.8.0 to 3.8.5.
What is the impact of CVE-2020-15801?
The impact of CVE-2020-15801 is that it allows code to be loaded from arbitrary locations, which can lead to unauthorized code execution or other malicious activities.
Is Microsoft Windows affected by CVE-2020-15801?
No, Microsoft Windows is not affected by CVE-2020-15801.