Логотип exploitDog
bind:CVE-2024-9287
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-9287

Количество 32

Количество 32

ubuntu логотип

CVE-2024-9287

около 1 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2024-9287

около 1 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2024-9287

около 1 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2024-9287

8 месяцев назад

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2024-9287

около 1 года назад

A vulnerability has been found in the CPython `venv` module and CLI wh ...

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0048-1

10 месяцев назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3959-1

12 месяцев назад

Security update for python312

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3958-1

12 месяцев назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3957-1

12 месяцев назад

Security update for python311

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3945-1

12 месяцев назад

Security update for python39

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3944-1

12 месяцев назад

Security update for python3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3929-1

12 месяцев назад

Security update for python36

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3924-1

12 месяцев назад

Security update for python310

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3879-1

около 1 года назад

Security update for python3

EPSS: Низкий
redos логотип

ROS-20250212-03

9 месяцев назад

Уязвимость python3

CVSS3: 7.8
EPSS: Низкий
rocky логотип

RLSA-2024:11111

8 месяцев назад

Moderate: python3.11 security update

EPSS: Низкий
rocky логотип

RLSA-2024:10979

11 месяцев назад

Moderate: python3.11 security update

EPSS: Низкий
github логотип

GHSA-grqq-hcc7-crmr

около 1 года назад

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2024-11111

11 месяцев назад

ELSA-2024-11111: python3.11 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10979

11 месяцев назад

ELSA-2024-10979: python3.11 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 6.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
0%
Низкий
около 1 года назад
msrc логотип
CVSS3: 7.8
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-9287

A vulnerability has been found in the CPython `venv` module and CLI wh ...

CVSS3: 7.8
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0048-1

Security update for python312

0%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3959-1

Security update for python312

0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3958-1

Security update for python311

0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3957-1

Security update for python311

0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3945-1

Security update for python39

0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3944-1

Security update for python3

0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3929-1

Security update for python36

0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3924-1

Security update for python310

0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3879-1

Security update for python3

0%
Низкий
около 1 года назад
redos логотип
ROS-20250212-03

Уязвимость python3

CVSS3: 7.8
0%
Низкий
9 месяцев назад
rocky логотип
RLSA-2024:11111

Moderate: python3.11 security update

0%
Низкий
8 месяцев назад
rocky логотип
RLSA-2024:10979

Moderate: python3.11 security update

0%
Низкий
11 месяцев назад
github логотип
GHSA-grqq-hcc7-crmr

A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

CVSS3: 7.8
0%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2024-11111

ELSA-2024-11111: python3.11 security update (MODERATE)

11 месяцев назад
oracle-oval логотип
ELSA-2024-10979

ELSA-2024-10979: python3.11 security update (MODERATE)

11 месяцев назад

Уязвимостей на страницу