{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"High"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"python-setuptools security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for python-setuptools is now available for openEuler-22.03-LTS-SP4",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"Setuptools is a collection of enhancements to the Python distutils that allow you to more easily build and distribute Python packages, especially ones that have dependencies on other packages.\n\nSecurity Fix(es):\n\nsetuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.(CVE-2025-47273)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for python-setuptools is now available for openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP3/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP2/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"High",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"python-setuptools",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2026-3376",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3376"
			},
			{
				"summary":"CVE-2025-47273",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-47273&packageName=python-setuptools"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47273"
			},
			{
				"summary":"openEuler-SA-2026-3376 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-3376.json"
			}
		],
		"title":"An update for python-setuptools is now available for openEuler-22.03-LTS-SP4",
		"tracking":{
			"initial_release_date":"2026-08-19T11:03:31+08:00",
			"revision_history":[
				{
					"date":"2026-08-19T11:03:31+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-08-19T11:03:31+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-08-19T11:03:31+08:00",
			"id":"openEuler-SA-2026-3376",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP4"
									},
									"product_id":"openEuler-22.03-LTS-SP4",
									"name":"openEuler-22.03-LTS-SP4"
								},
								"name":"openEuler-22.03-LTS-SP4",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"noarch",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP4"
									},
									"product_id":"python-setuptools-59.4.0-8.oe2203sp4.noarch.rpm",
									"name":"python-setuptools-59.4.0-8.oe2203sp4.noarch.rpm"
								},
								"name":"python-setuptools-59.4.0-8.oe2203sp4.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP4"
									},
									"product_id":"python-setuptools-help-59.4.0-8.oe2203sp4.noarch.rpm",
									"name":"python-setuptools-help-59.4.0-8.oe2203sp4.noarch.rpm"
								},
								"name":"python-setuptools-help-59.4.0-8.oe2203sp4.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP4"
									},
									"product_id":"python3-setuptools-59.4.0-8.oe2203sp4.noarch.rpm",
									"name":"python3-setuptools-59.4.0-8.oe2203sp4.noarch.rpm"
								},
								"name":"python3-setuptools-59.4.0-8.oe2203sp4.noarch.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP4"
									},
									"product_id":"python-setuptools-59.4.0-8.oe2203sp4.src.rpm",
									"name":"python-setuptools-59.4.0-8.oe2203sp4.src.rpm"
								},
								"name":"python-setuptools-59.4.0-8.oe2203sp4.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP4",
				"product_reference":"python-setuptools-59.4.0-8.oe2203sp4.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP4:python-setuptools-59.4.0-8.oe2203sp4.noarch",
					"name":"python-setuptools-59.4.0-8.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP4",
				"product_reference":"python-setuptools-help-59.4.0-8.oe2203sp4.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP4:python-setuptools-help-59.4.0-8.oe2203sp4.noarch",
					"name":"python-setuptools-help-59.4.0-8.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP4",
				"product_reference":"python3-setuptools-59.4.0-8.oe2203sp4.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP4:python3-setuptools-59.4.0-8.oe2203sp4.noarch",
					"name":"python3-setuptools-59.4.0-8.oe2203sp4.noarch as a component of openEuler-22.03-LTS-SP4"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS-SP4",
				"product_reference":"python-setuptools-59.4.0-8.oe2203sp4.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS-SP4:python-setuptools-59.4.0-8.oe2203sp4.src",
					"name":"python-setuptools-59.4.0-8.oe2203sp4.src as a component of openEuler-22.03-LTS-SP4"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2025-47273",
			"notes":[
				{
					"text":"setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-22.03-LTS-SP4:python-setuptools-59.4.0-8.oe2203sp4.noarch",
					"openEuler-22.03-LTS-SP4:python-setuptools-help-59.4.0-8.oe2203sp4.noarch",
					"openEuler-22.03-LTS-SP4:python3-setuptools-59.4.0-8.oe2203sp4.noarch",
					"openEuler-22.03-LTS-SP4:python-setuptools-59.4.0-8.oe2203sp4.src"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-22.03-LTS-SP4:python-setuptools-59.4.0-8.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python-setuptools-help-59.4.0-8.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python3-setuptools-59.4.0-8.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python-setuptools-59.4.0-8.oe2203sp4.src"
					],
					"details":"python-setuptools security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3376"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"HIGH",
						"baseScore":8.8,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
						"version":"3.1"
					},
					"products":[
						"openEuler-22.03-LTS-SP4:python-setuptools-59.4.0-8.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python-setuptools-help-59.4.0-8.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python3-setuptools-59.4.0-8.oe2203sp4.noarch",
						"openEuler-22.03-LTS-SP4:python-setuptools-59.4.0-8.oe2203sp4.src"
					]
				}
			],
			"threats":[
				{
					"details":"High",
					"category":"impact"
				}
			],
			"title":"CVE-2025-47273"
		}
	]
}