Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-53899

Опубликовано: 24 нояб. 2024
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

A flaw was found in the virtualenv Python package. Due to the improper handling of quotes in magic template strings, the virtual environment activation script is vulnerable to OS command injection,leading to the loss of confidentiality,integrity and availability of the system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-service-api-rhel9Affected
Red Hat OpenShift Container Platform 4python-virtualenvNot affected
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel8Not affected
Red Hat Satellite 6python-virtualenvNot affected
Red Hat Enterprise Linux 7 Extended Lifecycle Supportpython-virtualenvFixedRHSA-2024:1104816.12.2024
Red Hat Enterprise Linux 8python36FixedRHSA-2024:1095311.12.2024
Red Hat Enterprise Linux 8.2 Advanced Update Supportpython36FixedRHSA-2024:1109116.12.2024
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportpython36FixedRHSA-2025:000201.01.2025
Red Hat Enterprise Linux 8.4 Telecommunications Update Servicepython36FixedRHSA-2025:000201.01.2025
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutionspython36FixedRHSA-2025:000201.01.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2328554virtualenv: potential command injection via virtual environment activation scripts

EPSS

Процентиль: 70%
0.00643
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
nvd
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activat ...

suse-cvrf
7 месяцев назад

Security update for python3-virtualenv

EPSS

Процентиль: 70%
0.00643
Низкий

7.8 High

CVSS3