All errata/c10f2/ALT-PU-2025-16331-3
ALT-PU-2025-16331-3

Package update python3-module-virtualenv in branch c10f2

Version20.26.6-alt0.c10f2.1
Published2026-01-01
Max severityCRITICAL
Severity:

Closed issues (2)

BDU:2024-10842
CRITICAL9.8

Уязвимость сценариев активации конструктора виртуальной среды Python virtualenv, позволяющая нарушителю выполнить произвольные команды

Published: 2025-02-05Modified: 2025-08-13
CVSS 3.xCRITICAL 9.8
CVSS:3.x/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0CRITICAL 10.0
CVSS:2.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
References
CVE-2024-53899
HIGH7.8

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

Published: 2024-11-24Modified: 2025-02-10
CVSS 3.xHIGH 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H