{"id":116725,"date":"2024-06-23T03:39:41","date_gmt":"2024-06-23T01:39:41","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-python-pakete-js2py-zagruzhaemogo-bolee-milliona-raz-v-mesyacz"},"modified":"2024-06-23T03:39:41","modified_gmt":"2024-06-23T01:39:41","slug":"uyazvimost-v-python-pakete-js2py-zagruzhaemogo-bolee-milliona-raz-v-mesyacz","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-python-pakete-js2py-zagruzhaemogo-bolee-milliona-raz-v-mesyacz","title":{"rendered":"Eine Schwachstelle im Python-Paket Js2Py, das \u00fcber eine Million Mal pro Monat heruntergeladen wird","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Im Python-Paket Js2Py, das im vergangenen Monat 1,2 Millionen Mal heruntergeladen wurde, wurde eine Schwachstelle (CVE-2024-28397) entdeckt, die es erm\u00f6glicht, die Sandbox-Isolierung zu umgehen und Code im System auszuf\u00fchren, wenn speziell formatierte Daten in JavaScript verarbeitet werden. Diese Schwachstelle kann verwendet werden, um Angriffe auf Programme durchzuf\u00fchren, die Js2Py zur Ausf\u00fchrung von JavaScript-Code verwenden. Der Patch ist derzeit nur als Patch verf\u00fcgbar. Ein Prototyp des Exploits wurde zur \u00dcberpr\u00fcfung der Angriffs M\u00f6glichkeit vorbereitet.<\/p>\n<p>Das Paket Js2Py implementiert einen Interpreter und einen Transpiler f\u00fcr JavaScript, der es erm\u00f6glicht, JavaScript-Code in einer isolierten Umgebung auszuf\u00fchren <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/de\/vps\/abuzoustojchivye-vps\/\"   title=\"virtuellen Maschine\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"4341\">virtuellen Maschine<\/a> oder JavaScript in eine Darstellung in Python zu \u00fcbersetzen. Das Projekt ist vollst\u00e4ndig in Python geschrieben und verwendet keine externen JavaScript-Engines. In der Praxis wird die Bibliothek in verschiedenen Web-Crawlern, Download-Systemen und Website-Analysetools verwendet, die die Verarbeitung von Inhalten unterst\u00fctzen, die durch JavaScript-Code generiert werden. <\/p>\n<p>Zu den Anwendungen, die von der Schwachstelle betroffen sind, z\u00e4hlen Lightnovel Crawler (ein Tool zum Herunterladen von B\u00fcchern aus Online-Diensten und deren Speicherung in verschiedenen Formaten f\u00fcr das Offline-Lesen), cloudscraper (automatisches Umgehen von Schutzelementen gegen Bots, die in CDN Cloudflare verwendet werden) und pyLoad (ein Download-Manager, der die Verarbeitung von Seiten unterst\u00fctzt, die in JavaScript generiert werden). Bei der Verarbeitung von speziell formatiertem JavaScript-Inhalt in diesen Anwendungen kann ein Angreifer die Ausf\u00fchrung willk\u00fcrlichen Codes auf Systemebene erreichen.<\/p>\n<p>Die Schwachstelle ist in der Implementierung einer globalen Variablen innerhalb von js2py vorhanden, die es erm\u00f6glicht, auf ein Python-Objekt aus dem im isolierten Umfeld ausgef\u00fchrten JavaScript-Code zuzugreifen, ungeachtet des Aufrufs der Methode js2py.disable_pyimport(), um den Import von Python-Objekten zu deaktivieren. Um willk\u00fcrlichen Code im System auszuf\u00fchren, kann der Angreifer die Schwachstelle nutzen, um Zugriff auf das Popen-Objekt aus dem Python-Modul subprocess zu erhalten. Bemerkenswert ist, dass die \u00c4nderungen zur Behebung der Schwachstelle am ersten M\u00e4rz im Projekt Js2Py eingereicht wurden, aber in dreieinhalb Monaten nicht akzeptiert wurden.<br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=61421\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 Python-\u043f\u0430\u043a\u0435\u0442\u0435 Js2Py, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0437\u0430\u0433\u0440\u0443\u0436\u0435\u043d \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u043c\u0435\u0441\u044f\u0446\u0435 1.2 \u043c\u043b\u043d \u0440\u0430\u0437, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-28397), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 sandbox-\u0438\u0437\u043e\u043b\u044f\u0446\u0438\u044e \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u043d\u0430 JavaScript. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u044c\u0441\u044f \u0434\u043b\u044f \u0430\u0442\u0430\u043a\u0438 \u043d\u0430 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u044b, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u044e\u0449\u0438\u0435 Js2Py \u0434\u043b\u044f \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044f JavaScript-\u043a\u043e\u0434\u0430. \u0418\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043f\u043e\u043a\u0430 \u0434\u043e\u0441\u0442\u0443\u043f\u043d\u043e \u0442\u043e\u043b\u044c\u043a\u043e \u0432 \u0432\u0438\u0434\u0435 \u043f\u0430\u0442\u0447\u0430. \u0414\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u0430\u0442\u0430\u043a\u0438 \u043f\u043e\u0434\u0433\u043e\u0442\u043e\u0432\u043b\u0435\u043d \u043f\u0440\u043e\u0442\u043e\u0442\u0438\u043f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-116725","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 Python-\u043f\u0430\u043a\u0435\u0442\u0435 Js2Py, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0437\u0430\u0433\u0440\u0443\u0436\u0435\u043d \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u043c\u0435\u0441\u044f\u0446\u0435 1.2 \u043c\u043b\u043d \u0440\u0430\u0437, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-28397), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 sandbox-\u0438\u0437\u043e\u043b\u044f\u0446\u0438\u044e \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-python-pakete-js2py-zagruzhaemogo-bolee-milliona-raz-v-mesyacz\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Python-\u043f\u0430\u043a\u0435\u0442\u0435 Js2Py, \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u043e\u0433\u043e \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0440\u0430\u0437 \u0432 \u043c\u0435\u0441\u044f\u0446 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 Python-\u043f\u0430\u043a\u0435\u0442\u0435 Js2Py, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0437\u0430\u0433\u0440\u0443\u0436\u0435\u043d \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u043c\u0435\u0441\u044f\u0446\u0435 1.2 \u043c\u043b\u043d \u0440\u0430\u0437, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-28397), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 sandbox-\u0438\u0437\u043e\u043b\u044f\u0446\u0438\u044e \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-python-pakete-js2py-zagruzhaemogo-bolee-milliona-raz-v-mesyacz\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2024-06-23T01:39:41+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2024-06-23T01:39:41+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Schwachstelle im Python-Paket Js2Py, das \u00fcber eine Million Mal pro Monat heruntergeladen wird | ProHoster","description":"Im Python-Paket Js2Py, das im vergangenen Monat 1,2 Millionen Mal heruntergeladen wurde, wurde eine Schwachstelle (CVE-2024-28397) entdeckt, die es erm\u00f6glicht, die Sandbox-Isolierung zu umgehen und Code im System auszuf\u00fchren beim Umgang mit speziell formatierten.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-python-pakete-js2py-zagruzhaemogo-bolee-milliona-raz-v-mesyacz","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Python-\u043f\u0430\u043a\u0435\u0442\u0435 Js2Py, \u0437\u0430\u0433\u0440\u0443\u0436\u0430\u0435\u043c\u043e\u0433\u043e \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0440\u0430\u0437 \u0432 \u043c\u0435\u0441\u044f\u0446 | ProHoster","og:description":"\u0412 Python-\u043f\u0430\u043a\u0435\u0442\u0435 Js2Py, \u043a\u043e\u0442\u043e\u0440\u044b\u0439 \u0431\u044b\u043b \u0437\u0430\u0433\u0440\u0443\u0436\u0435\u043d \u0432 \u043f\u0440\u043e\u0448\u043b\u043e\u043c \u043c\u0435\u0441\u044f\u0446\u0435 1.2 \u043c\u043b\u043d \u0440\u0430\u0437, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2024-28397), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 sandbox-\u0438\u0437\u043e\u043b\u044f\u0446\u0438\u044e \u0438 \u0432\u044b\u043f\u043e\u043b\u043d\u0438\u0442\u044c \u043a\u043e\u0434 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u043f\u0440\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0435 \u0441\u043f\u0435\u0446\u0438\u0430\u043b\u044c\u043d\u043e \u043e\u0444\u043e\u0440\u043c\u043b\u0435\u043d\u043d\u044b\u0445.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/uyazvimost-v-python-pakete-js2py-zagruzhaemogo-bolee-milliona-raz-v-mesyacz","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2024-06-23T01:39:41+00:00","article:modified_time":"2024-06-23T01:39:41+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"116725","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 02:44:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 02:44:19","updated":"2026-01-23 02:44:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/116725","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=116725"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/116725\/revisions"}],"predecessor-version":[{"id":164216,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/116725\/revisions\/164216"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=116725"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=116725"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=116725"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}