CVE-2024-53899

Source
https://cve.org/CVERecord?id=CVE-2024-53899
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-53899.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-53899
Aliases
Downstream
AZL (2)
BELL (1)
CGA (8)
CLSA (2)
DEBIAN (1)
ECHO (1)
OESA (1)
openSUSE (1)
RHSA (6)
RLSA (1)
ROOT (1)
SUSE (2)
UBUNTU (1)
Related
Published
2024-11-24T00:00:00Z
Modified
2026-08-12T03:51:42Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

Database specific
{
    "cna_assigner":  "mitre",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/53xxx/CVE-2024-53899.json"
}
References

Affected packages

Git / github.com/pypa/virtualenv

Affected ranges

Type
GIT
Repo
https://github.com/pypa/virtualenv
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:virtualenv:virtualenv:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "20.26.6"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

20.*
20.0.0b1
20.0.0b2
20.0.32
20.0.7
20.24.3
20.3.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-53899.json"