First published: Sun Nov 24 2024(Updated: )
Last updated 25 February 2025
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/virtualenv | <20.26.6 | 20.26.6 |
debian/python-virtualenv | <=20.4.0+ds-2+deb11u1<=20.17.1+ds-1 | 20.29.1+ds-1 |
virtualenv | <20.26.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-53899 is classified as a command injection vulnerability, which can compromise the security of the system.
To fix CVE-2024-53899, update virtualenv to version 20.26.6 or later.
CVE-2024-53899 affects virtualenv versions prior to 20.26.6.
If left unresolved, CVE-2024-53899 could allow an attacker to execute arbitrary commands on the system through manipulated activation scripts.
CVE-2024-53899 is not the same as CVE-2024-9287, although both involve vulnerabilities in virtualenv.