Vulnérabilité · NVD
CVE-2024-9287
MEDIUM 7.8
Échelle bulletin éditeur — CVSS NVD en attente
EN A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.
Vecteur d'attaque : Local
Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
0.65%
exploit très peu probable
percentile 47.7%
Apps suivies liées à cette CVE
Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.
Configurations CPE vulnérables (6)
| Vendor | Produit | Plateforme | Versions | CPE 2.3 URI |
|---|---|---|---|---|
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | <3.9.21 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≥3.10.0 <3.10.16 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≥3.11.0 <3.11.11 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≥3.12.0 <3.12.8 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | ≥3.13.0 <3.13.1 | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
| python |
python Toutes plateformes (wildcard)
|
Toutes plateformes (wildcard) | — | cpe:2.3:a:python:python:3.14.0:alpha1:*:*:*:*:*:* |