All errata/p10/ALT-PU-2025-6288-5
ALT-PU-2025-6288-5

Package update python3-module-virtualenv in branch p10

Version20.30.0-alt0.p10.1
Published2026-02-04
Max severityCRITICAL
Severity:

Closed issues (3)

BDU:2024-10842
CRITICAL9.8

Уязвимость сценариев активации конструктора виртуальной среды Python virtualenv, позволяющая нарушителю выполнить произвольные команды

Published: 2025-02-05Modified: 2025-08-13
CVSS 3.xCRITICAL 9.8
CVSS:3.x/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.0CRITICAL 10.0
CVSS:2.0/AV:N/AC:L/Au:N/C:C/I:C/A:C
References
CVE-2024-53899
HIGH7.8

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

Published: 2024-11-24Modified: 2025-02-10
CVSS 3.xHIGH 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
GHSA-rqc4-2hc7-8c8v
HIGH8.4

virtualenv allows command injection through activation scripts for a virtual environment

Published: 2024-11-24Modified: 2025-01-21
CVSS 3.xHIGH 8.4
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H