Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2024-53899

Disclosure Date: November 24, 2024 (last updated February 11, 2025)
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
Attacker Value
Unknown

CVE-2020-11073

Disclosure Date: May 13, 2020 (last updated February 21, 2025)
In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could run arbitrary code without any user interaction. This is fixed in version: 1.16.0
Attacker Value
Unknown

CVE-2013-5123

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.