Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-53899

Опубликовано: 24 нояб. 2024
Источник: debian
EPSS Низкий

Описание

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-virtualenvfixed20.26.6+ds-1package
python-virtualenvno-dsabookwormpackage
python-virtualenvpostponedbullseyepackage

Примечания

  • https://github.com/pypa/virtualenv/issues/2768

  • https://github.com/pypa/virtualenv/pull/2771

  • Fixed by: https://github.com/pypa/virtualenv/commit/86dddeda7c991f8529e1995bbff280fb7b761972 (20.26.6)

EPSS

Процентиль: 70%
0.00643
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
redhat
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
nvd
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
msrc
6 месяцев назад

Описание отсутствует

suse-cvrf
7 месяцев назад

Security update for python3-virtualenv

EPSS

Процентиль: 70%
0.00643
Низкий