CVE-2024-53899: virtualenv allows command injection through activation scripts for a virtual environment
(updated )
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
References
- github.com/advisories/GHSA-rqc4-2hc7-8c8v
- github.com/pypa/advisory-database/tree/main/vulns/virtualenv/PYSEC-2024-187.yaml
- github.com/pypa/virtualenv
- github.com/pypa/virtualenv/issues/2768
- github.com/pypa/virtualenv/pull/2771
- github.com/pypa/virtualenv/releases/tag/20.26.6
- nvd.nist.gov/vuln/detail/CVE-2024-53899
Detect and mitigate CVE-2024-53899 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →