First published: Sun Nov 24 2024(Updated: )
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as <a href="https://access.redhat.com/security/cve/CVE-2024-9287">CVE-2024-9287</a>.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Virtualenv Virtualenv | <20.26.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.