跳转到帖子

Red Hat: CVE-2024-53899: virtualenv: potential command injection via virtual environment activation scripts (Multiple Advisories)

recommended_posts

发布于
  • Members

Red Hat: CVE-2024-53899: virtualenv: potential command injection via virtual environment activation scripts (Multiple Advisories)

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
11/24/2024
Created
02/11/2025
Added
02/10/2025
Modified
02/12/2025

Description

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

Solution(s)

  • redhat-upgrade-python-nose-docs
  • redhat-upgrade-python-pymongo-debuginfo
  • redhat-upgrade-python-pymongo-debugsource
  • redhat-upgrade-python-pymongo-doc
  • redhat-upgrade-python-sqlalchemy-doc
  • redhat-upgrade-python-virtualenv-doc
  • redhat-upgrade-python3-bson
  • redhat-upgrade-python3-bson-debuginfo
  • redhat-upgrade-python3-distro
  • redhat-upgrade-python3-docs
  • redhat-upgrade-python3-docutils
  • redhat-upgrade-python3-nose
  • redhat-upgrade-python3-pygments
  • redhat-upgrade-python3-pymongo
  • redhat-upgrade-python3-pymongo-debuginfo
  • redhat-upgrade-python3-pymongo-gridfs
  • redhat-upgrade-python3-pymysql
  • redhat-upgrade-python3-scipy
  • redhat-upgrade-python3-scipy-debuginfo
  • redhat-upgrade-python3-sqlalchemy
  • redhat-upgrade-python3-virtualenv
  • redhat-upgrade-python3-wheel
  • redhat-upgrade-python3-wheel-wheel
  • redhat-upgrade-python36
  • redhat-upgrade-python36-debug
  • redhat-upgrade-python36-devel
  • redhat-upgrade-python36-rpm-macros
  • redhat-upgrade-scipy-debugsource

References

  • CVE-2024-53899
  • RHSA-2024:10953
  • RHSA-2024:11093
  • 查看数 696
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…