Description

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

INFO

Published Date :

2024-11-24T00:00:00.000Z

Last Modified :

2024-11-24T18:25:36.636Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-53899 vulnerability.

Vendors Products
Redhat
  • Enterprise Linux
  • Openshift Devspaces
  • Rhel Aus
  • Rhel E4s
  • Rhel Els
  • Rhel Eus
  • Rhel Tus
Virtualenv
  • Virtualenv

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact