First published: Sun Nov 24 2024(Updated: )
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as <a href="https://access.redhat.com/security/cve/CVE-2024-9287">CVE-2024-9287</a>.
Affected Software | Affected Version | How to fix |
---|---|---|
virtualenv | <20.26.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2328554 is categorized as a potential command injection vulnerability in virtualenv.
To fix REDHAT-BUG-2328554, upgrade virtualenv to version 20.26.6 or later.
Versions of virtualenv prior to 20.26.6 are affected by REDHAT-BUG-2328554.
REDHAT-BUG-2328554 is a command injection vulnerability that arises from improper handling of magic template strings.
No, REDHAT-BUG-2328554 is distinct from CVE-2024-9287.