Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Vulnérabilité · NVD

CVE-2024-9287

CVE-2024-9287, classée medium par l'éditeur : 3 apps suivies concernées, toutes corrigées ou à statut indéterminable en version courante.

Gravité (CVSS)
7.8

CVSS base ; la gravité est une note éditeur (échelle différente)

Exploitation
0.6 %

EPSS, prédiction à 30 jours

Apps suivies
3
Encore exposées
0
Échelle bulletin éditeur : CVSS NVD en attente

EN A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual environment were not quoted properly, allowing the creator to inject commands into virtual environment "activation" scripts (ie "source venv/bin/activate"). This means that attacker-controlled virtual environments are able to run commands when the virtual environment is activated. Virtual environments which are not created by an attacker or which aren't activated before being used (ie "./venv/bin/python") are not affected.

Vecteur d'attaque : Local Sans interaction utilisateur
Voir le vecteur CVSS brut
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS 0.65% exploit très peu probable percentile 49.3%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

Configurations CPE vulnérables (6)
Vendor Produit Versions
python python
Toutes plateformes (wildcard)
<3.9.21
python python
Toutes plateformes (wildcard)
≥3.10.0 <3.10.16
python python
Toutes plateformes (wildcard)
≥3.11.0 <3.11.11
python python
Toutes plateformes (wildcard)
≥3.12.0 <3.12.8
python python
Toutes plateformes (wildcard)
≥3.13.0 <3.13.1
python python
Toutes plateformes (wildcard)
-
Voir sur NVD ↗ Advisory · mail.python.org Advisory · github.com