Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rqc4-2hc7-8c8v

Опубликовано: 24 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.4

Описание

virtualenv allows command injection through activation scripts for a virtual environment

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

Пакеты

Наименование

virtualenv

pip
Затронутые версииВерсия исправления

< 20.26.6

20.26.6

EPSS

Процентиль: 70%
0.00643
Низкий

8.4 High

CVSS3

Дефекты

CWE-77
CWE-78

Связанные уязвимости

CVSS3: 7.8
ubuntu
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
redhat
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
nvd
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activat ...

EPSS

Процентиль: 70%
0.00643
Низкий

8.4 High

CVSS3

Дефекты

CWE-77
CWE-78