{"id":"CVE-2024-47532","aliases":["GHSA-5rfv-66g4-jr8h","PYSEC-2024-186"],"url":"https://o3.security/vulnerability/CVE-2024-47532","summary":"RestrictedPython information leakage via `AttributeError.obj` and the `string` module","details":"RestrictedPython is a restricted execution environment for Python to run untrusted code. A user can gain access to protected (and potentially sensible) information indirectly via AttributeError.obj and the string module. The problem will be fixed in version 7.3. As a workaround, If the application does not require access to the module string, it can remove it from RestrictedPython.Utilities.utility_builtins or otherwise do not make it available in the restricted execution environment.","published":"2024-09-30T15:29:57.907Z","modified":"2026-08-08T03:48:07.455343704Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"restrictedpython","fixedVersion":"7.3"}],"fix":{"url":"https://github.com/zopefoundation/RestrictedPython/commit/d701cc36cccac36b21fa200f1f2d1945a9a215e6","label":"zopefoundation/RestrictedPython@d701cc3"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47532.json"},{"type":"ADVISORY","url":"https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-5rfv-66g4-jr8h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47532"},{"type":"FIX","url":"https://github.com/zopefoundation/RestrictedPython/commit/d701cc36cccac36b21fa200f1f2d1945a9a215e6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:07.455343704Z"}}