Command InjectionAffected versions of this package are vulnerable to Command Injection via the BatchActivator.quote method in src/virtualenv/activation/batch/__init__.py, which previously returned its input string unchanged. When a virtualenv is created in a path containing cmd.exe operator characters such as &, |, <, >, ^, !, or ", those characters are embedded verbatim into the generated activate.bat script inside @set "VAR=value" statements. An attacker who controls the virtualenv path or environment values can inject arbitrary cmd.exe commands that execute when a user sources the activation script.
How to fix Command Injection? Upgrade virtualenv to version 21.7.12 or higher.
| |
Resources Downloaded over Insecure ProtocolAffected versions of this package are vulnerable to Resources Downloaded over Insecure Protocol via the download_wheel function in src/virtualenv/seed/wheels/acquire.py, which invokes pip download to fetch seed wheels without subsequently verifying the downloaded wheel's SHA-256 digest against the PyPI JSON API. An attacker positioned between the client and the package index can serve a tampered wheel that pip accepts, and because no digest check is performed, the malicious wheel is silently used to seed new virtual environments, leading to full compromise of the seeded environment's integrity and confidentiality.
Note: This is only exploitable when the default PyPI index is in use and an attacker can intercept or manipulate the download (e.g. via a MitM or a compromised mirror).
How to fix Resources Downloaded over Insecure Protocol? Upgrade virtualenv to version 21.7.12 or higher.
| |
Command InjectionAffected versions of this package are vulnerable to Command Injection via path interpolation in the generated activate.sh (bash) and activate.fish (fish) activation scripts. When a virtualenv is created with a path containing shell metacharacters, those characters are embedded unquoted into the activation script, allowing an attacker who controls the virtualenv path to inject arbitrary shell commands that execute when a user sources the activation script.
How to fix Command Injection? Upgrade virtualenv to version 21.7.13 or higher.
| |