DNA View

High Severity Vulnerability

This vulnerability has been rated as High severity. Immediate action is recommended.

CVE-2023-6597

High
Low Medium High Critical
7.8
CVSS Score
Published: Mar 19, 2024
Last Modified: Nov 03, 2025

Vulnerability Description

An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1, 3.11.7, 3.10.13, 3.9.18, and 3.8.18 and prior.

The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Attack Vector
L
Attack Complexity
H
Privileges Required
N
User Interaction
N
Scope
C
Confidentiality
H
Integrity
H
Availability
N

Available Security Patches

3 patches available from vendors

View All Patches
Microsoft

2024-Sep-CVE-2023-6597

CVE-2023-6597: None

Severity
Unknown
Released
Oct 11, 2025
Security Update
Microsoft

2024-Mar-CVE-2023-6597

CVE-2023-6597: An issue was found in the CPython `tempfile.TemporaryDirectory` class affecting versions 3.12.1 3.11.7 3.10.13 3.9.18 and 3.8.18 and prior. The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.

Severity
Unknown
Released
Sep 04, 2025
Security Update
Oracle

CPUJAN2025

Oracle Critical Patch Update Advisory - January 2025

Severity
Critical
Released
Jan 21, 2025
Restart Required
Security Update

References & Resources

Severity Details

7.8
out of 10.0
High

Key Information

Published Date
March 19, 2024