Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-53899

Опубликовано: 24 нояб. 2024
Источник: debian
EPSS Низкий

Описание

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-virtualenvfixed20.26.6+ds-1package
python-virtualenvno-dsabookwormpackage
python-virtualenvpostponedbullseyepackage

Примечания

  • https://github.com/pypa/virtualenv/issues/2768

  • https://github.com/pypa/virtualenv/pull/2771

  • Fixed by: https://github.com/pypa/virtualenv/commit/86dddeda7c991f8529e1995bbff280fb7b761972 (20.26.6)

EPSS

Процентиль: 74%
0.00877
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
9 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
redhat
9 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
nvd
9 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
msrc
8 месяцев назад

Описание отсутствует

suse-cvrf
9 месяцев назад

Security update for python3-virtualenv

EPSS

Процентиль: 74%
0.00877
Низкий