Логотип exploitDog
bind:CVE-2024-9287
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-9287

Количество 34

Количество 34

ubuntu логотип

CVE-2024-9287

больше 1 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2024-9287

больше 1 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2024-9287

больше 1 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2024-9287

11 месяцев назад

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2024-9287

больше 1 года назад

A vulnerability has been found in the CPython `venv` module and CLI wh ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0048-1

около 1 года назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3959-1

около 1 года назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3958-1

около 1 года назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3957-1

около 1 года назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3945-1

около 1 года назад

Security update for python39

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3944-1

около 1 года назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3929-1

около 1 года назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3924-1

около 1 года назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3879-1

больше 1 года назад

Security update for python3

EPSS: Низкий
rocky логотип

RLSA-2024:11111

11 месяцев назад

Moderate: python3.11 security update

EPSS: Низкий
rocky логотип

RLSA-2024:10979

около 1 года назад

Moderate: python3.11 security update

EPSS: Низкий
github логотип

GHSA-grqq-hcc7-crmr

больше 1 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2024-11111

около 1 года назад

ELSA-2024-11111: python3.11 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10979

около 1 года назад

ELSA-2024-10979: python3.11 security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2025-03332

больше 1 года назад

Уязвимость модуля cpython языка программирования Python, позволяющая нарушителю нарушить выполнить произвольный код

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 6.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 7.8
0%
Низкий
11 месяцев назад
debian логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI wh ...

CVSS3: 7.8
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0048-1

Security update for python312

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3959-1

Security update for python312

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3958-1

Security update for python311

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3957-1

Security update for python311

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3945-1

Security update for python39

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3944-1

Security update for python3

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3929-1

Security update for python36

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3924-1

Security update for python310

0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3879-1

Security update for python3

0%
Низкий
больше 1 года назад
rocky логотип
RLSA-2024:11111

Moderate: python3.11 security update

0%
Низкий
11 месяцев назад
rocky логотип
RLSA-2024:10979

Moderate: python3.11 security update

0%
Низкий
около 1 года назад
github логотип
GHSA-grqq-hcc7-crmr

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2024-11111

ELSA-2024-11111: python3.11 security update (MODERATE)

около 1 года назад
oracle-oval логотип
ELSA-2024-10979

ELSA-2024-10979: python3.11 security update (MODERATE)

около 1 года назад
fstec логотип
BDU:2025-03332

Уязвимость модуля cpython языка программирования Python, позволяющая нарушителю нарушить выполнить произвольный код

CVSS3: 7.8
0%
Низкий
больше 1 года назад

Уязвимостей на страницу