/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-x7q9-wmjh-w3xm

Published

Last updated

https://images.chainguard.dev/security/CGA-x7q9-wmjh-w3xm
Package

python-3.10

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2023-38898
  • GHSA-73qf-r7xg-3ghc

Severity

5.3

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2023-38898

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

This CVE is claimed to be inaccurate and is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases and up); (2) there are no common scenarios in which an adversary can call _asyncio._swap_current_task but does not already have the ability to call arbitrary functions; and (3) there are no common scenarios in which sensitive information, which is not already accessible to an adversary, becomes accessible through this bug. Affected versions can be found under the tags here in this commit https://github.com/python/cpython/commit/a474e04388c2ef6aca75c26cb70a1b6200235feb and PR that resolved the bug here https://github.com/python/cpython/issues/105987

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing