CVE-2023-41105An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but that filename is no longer rejected in Python 3.11.x.
CWE-426
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 3 years.
CVSS E:U
Not a Java vulnerability. Outside ARMR's domain entirely.
| Decided by | non-java-upstream : A root cause in non-Java code: an OS kernel, a C library, or a bundled runtime |
|---|---|
| Finding | The issuing CNA declared no affected product. The CVE's CPE data names python/python, whose code is not Java, so that is what the CVE is about — every other product on the record bundles it. |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
1 metric
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
NVD | Primary | published |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update July 2024 ↗ | CPU | 2024-Q3 | Oracle Siebel CRM / Siebel Cloud Manager (Python) (23.11 and prior) |
| Oracle Critical Patch Update January 2024 ↗ | CPU | 2024-Q1 | Oracle MySQL / Workbench (Python) (8.0.34 and prior) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle MySQL | Workbench (Python) | 8.0.34 and prior | |
| Oracle Siebel CRM | Siebel Cloud Manager (Python) | 23.11 and prior |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | netapp | active iq unified manager | generic | any version |
| nvd | python | python | generic | ≥ 3.11.0 and ≤ 3.11.4 |
| Published | 2023-08-23 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |