Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-53899

Опубликовано: 24 нояб. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.8

Описание

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

РелизСтатусПримечание
devel

not-affected

20.27.0+ds-1
esm-apps/bionic

not-affected

code not present
esm-apps/focal

released

20.0.17-1ubuntu0.4+esm1
esm-apps/jammy

released

20.13.0+ds-2ubuntu0.1~esm1
esm-apps/noble

released

20.25.0+ds-2ubuntu0.1~esm1
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

needs-triage

focal

ignored

end of standard support, was needed
jammy

needed

noble

needed

Показывать по

EPSS

Процентиль: 70%
0.00643
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
nvd
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activat ...

suse-cvrf
7 месяцев назад

Security update for python3-virtualenv

EPSS

Процентиль: 70%
0.00643
Низкий

7.8 High

CVSS3