---
title: "CVE-2024-6345\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2024-6345?format=md
keywords: index, follow
---

# CVE-2024-6345

Publication date 15 July 2024

Last updated 19 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2024-6345?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability in the package\_index module of pypa/setuptools versions up
to 69.1.1 allows for remote code execution via its download functions.
These functions, which are used to download packages from URLs provided by
users or retrieved from package index servers, are susceptible to code
injection. If these functions are exposed to user-controlled inputs, such
as package URLs, they can execute arbitrary commands on the system. The
issue is fixed in version 70.0.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2024-6345?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| python-pip | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Fixed 20.0.2-5ubuntu1.10+esm2  Ubuntu Pro |
| 18.04 LTS bionic | Fixed 9.0.1-2.3~ubuntu1.18.04.8+esm4  Ubuntu Pro |
| 16.04 LTS xenial | Fixed 8.1.1-2ubuntu0.6+esm8  Ubuntu Pro |
| 14.04 LTS trusty | Fixed 1.5.4-1ubuntu4+esm5  Ubuntu Pro |
| python-setuptools | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 22.04 LTS jammy | Fixed 44.1.1-1.2ubuntu0.22.04.1+esm1  Ubuntu Pro |
| 20.04 LTS focal | Fixed 44.0.0-2ubuntu0.1+esm1  Ubuntu Pro |
| 18.04 LTS bionic | Fixed 39.0.1-2ubuntu0.1+esm1  Ubuntu Pro |
| 16.04 LTS xenial | Fixed 20.7.0-1ubuntu0.1~esm2  Ubuntu Pro |
| 14.04 LTS trusty | Fixed 3.3-1ubuntu2+esm2  Ubuntu Pro |
| setuptools | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Fixed 68.1.2-2ubuntu1.1 |
| 22.04 LTS jammy | Fixed 59.6.0-1.2ubuntu0.22.04.2 |
| 20.04 LTS focal | Fixed 45.2.0-1ubuntu0.2 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

On focal and earlier, the python-pip package bundles
python-setuptools binaries when built. After updating
python-setuptools, a no-change rebuild of python-pip is
required. On jammy and later, python-setuptools is bundled in
the python-pip package and needs to be patched.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6345)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2024-6345)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2024-6345)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2024-6345)

### Related Ubuntu Security Notices (USN)

+ [USN-7002-1](https://usn.ubuntu.com/USN-7002-1)
+ Setuptools vulnerability
+ 12 September 2024

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2024-6345>
* <https://huntr.com/bounties/d6362117-ad57-4e83-951f-b8141c6e7ca5>
* <https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0>
