{"id":"BIT-miniconda-2023-35845","details":"Anaconda 3 2023.03-1-Linux allows local users to disrupt TLS certificate validation by modifying the cacert.pem file used by the installed pip program. This occurs because many files are installed as world-writable on Linux, ignoring umask, even when these files are installed as root. Miniconda is also affected.","aliases":["CVE-2023-35845"],"modified":"2024-02-19T10:36:29.170Z","published":"2024-01-31T15:16:52.276Z","database_specific":{"cpes":["cpe:2.3:a:anaconda:anaconda3:2023.03-1:*:*:*:*:*:*:*"],"severity":"Medium"},"references":[{"type":"WEB","url":"https://uponfurtherinvestigation.blogspot.com/2023/06/cve-2023-35845-anaconda3-creates.html"}],"affected":[{"package":{"name":"miniconda","ecosystem":"Bitnami","purl":"pkg:bitnami/miniconda"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2023.03-1.0"},{"last_affected":"2023.03-1.0"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/miniconda/BIT-miniconda-2023-35845.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}],"schema_version":"1.7.3"}