RHSA-2022:5234: Moderate: python-virtualenv security update
The virtualenv tool creates isolated Python environments. The virtualenv tool is a successor to workingenv, and an extension of virtual-python.Security Fix(es): python-pip: directory traversal in _download_http_url() function in src/pip/_internal/download.py (CVE-2019-20916) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5234?
The severity of RHSA-2022:5234 is classified as moderate.
How do I fix RHSA-2022:5234?
To fix RHSA-2022:5234, update the python-virtualenv package to version 15.1.0-7.el7_9 or higher.
What vulnerabilities are addressed in RHSA-2022:5234?
RHSA-2022:5234 addresses a directory traversal vulnerability in the _download_http_url() function.
Which versions of python-virtualenv are affected by RHSA-2022:5234?
Versions of python-virtualenv prior to 15.1.0-7.el7_9 are affected by RHSA-2022:5234.
Is there a workaround for RHSA-2022:5234?
There are no specified workarounds for RHSA-2022:5234; applying the patch is recommended.