Skip to content

fix(python-virtualenv): CVE-2024-53899#7

Open
deepin-ci-robot wants to merge 1 commit intomasterfrom
fix/CVE-2024-53899
Open

fix(python-virtualenv): CVE-2024-53899#7
deepin-ci-robot wants to merge 1 commit intomasterfrom
fix/CVE-2024-53899

Conversation

@deepin-ci-robot
Copy link
Copy Markdown
Contributor

CVE 修复

CVE ID: CVE-2024-53899

漏洞描述: virtualenv 20.26.6 之前版本存在命令注入漏洞。由于激活脚本模板中的魔法字符串引用处理不当,攻击者可能通过精心构造的输入在虚拟环境激活时执行任意命令。

修复方案: 正确引用激活脚本模板中的字符串占位符,防止命令注入。

受影响版本: < 20.26.6

当前版本: 20.25.1+ds-1

验证状态: ✅ 已通过 quilt 验证


Upstream PR: pypa/virtualenv#2771
Upstream Release: https://github.com/pypa/virtualenv/releases/tag/20.26.6

Generated by: CVE-Fixer Agent
Co-Authored-By: hudeng hudeng@deepin.org

Fix command injection in activation scripts.

Properly quote string placeholders in activation script templates
to mitigate potential command injection vulnerability.

Upstream: pypa/virtualenv#2771
Upstream: https://github.com/pypa/virtualenv/releases/tag/20.26.6
Generated-By: glm-5.1
Co-Authored-By: hudeng <hudeng@deepin.org>
@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 7, 2026

TAG Bot

TAG: 20.25.1+ds-1deepin1
EXISTED: no
DISTRIBUTION: unstable

@hudeng-go
Copy link
Copy Markdown

/integrate

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 8, 2026

AutoIntegrationPr Bot
auto integrate with pr url: deepin-community/Repository-Integration#3969
PrNumber: 3969
PrBranch: auto-integration-25545843631

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants