Aller au contenu
Appaloosa Scout

Vulnérabilité · NVD

CVE-2024-9287

MEDIUM 7.8 Échelle bulletin éditeur — CVSS NVD en attente

EN A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

Vecteur d'attaque : Local Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS 0.65% exploit très peu probable percentile 47.7%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

  • Python 3.12 Windows winget:Python.Python.3.12
    Affecté Corrigé Dernière suivie 3.12.10 indéterminé
Configurations CPE vulnérables (6)
Vendor Produit Versions
python python
Toutes plateformes (wildcard)
<3.9.21
python python
Toutes plateformes (wildcard)
≥3.10.0 <3.10.16
python python
Toutes plateformes (wildcard)
≥3.11.0 <3.11.11
python python
Toutes plateformes (wildcard)
≥3.12.0 <3.12.8
python python
Toutes plateformes (wildcard)
≥3.13.0 <3.13.1
python python
Toutes plateformes (wildcard)
Voir sur NVD ↗ Advisory · mail.python.org Advisory · github.com