REDHAT-BUG-2328554: Command Injection
Published Nov 24, 2024
·Updated
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
Affected Software
1 affected component
virtualenv virtualenv<20.26.6
Event History
Nov 24, 2024
Data Sourced
via Red Hat·05:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2328554?
The severity of REDHAT-BUG-2328554 is categorized as a potential command injection vulnerability in virtualenv.
2
How do I fix REDHAT-BUG-2328554?
To fix REDHAT-BUG-2328554, upgrade virtualenv to version 20.26.6 or later.
3
Which versions of virtualenv are affected by REDHAT-BUG-2328554?
Versions of virtualenv prior to 20.26.6 are affected by REDHAT-BUG-2328554.
4
What type of vulnerability is REDHAT-BUG-2328554?
REDHAT-BUG-2328554 is a command injection vulnerability that arises from improper handling of magic template strings.
5
Is REDHAT-BUG-2328554 the same as CVE-2024-9287?
No, REDHAT-BUG-2328554 is distinct from CVE-2024-9287.