GHSA-cgfh-jp5w-8cmx
MEDIUMAn issue in Python cpython v.3.7 allows an attacker to obtain sensitive information via the asyncio.swapcurrenttask component. NOTE: this is disputed by the vendor because (1) neither 3.7 nor any other release is affected (it is a bug in some 3.12 pre-releases); (2) there are no common scenarios in which an adversary can call asyncio.swapcurrenttask but does not already have the ability to call ar
- Affected
- >=0, <3.6.13, >=3.7.0, <3.7.10, >=3.8.0, <3.8.7, >=3.9.0, <3.9.1
- Fixed in
- not stated
- Published
- 2024-03-06
- Source
- osv