CVE-2023-38898: Medium severity python 2.7 vulnerability
DISPUTED An issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the asyncio.swapcurrenttask component. NOTE: this is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases); (2) there are no common scenarios in which an adversary can call asyncio.swapcurrenttask but does not already have the ability to call arbitrary functions; and (3) there are no common scenarios in which sensitive information, which is not already accessible to an adversary, becomes accessible through this bug.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-38898?
CVE-2023-38898 is an issue in Python cpython v.3.7 that allows an attacker to obtain sensitive information.
What is the severity of CVE-2023-38898?
The severity of CVE-2023-38898 is medium with a severity value of 5.3.
How does CVE-2023-38898 affect Python?
CVE-2023-38898 affects Python cpython v.3.7.
How can an attacker exploit CVE-2023-38898?
An attacker can exploit CVE-2023-38898 by leveraging the _asyncio._swap_current_task component to obtain sensitive information.
Is Python 3.7 impacted by CVE-2023-38898?
No, Python 3.7 is not affected by CVE-2023-38898, as it is a bug in some 3.12 pre-releases.