virtualenv@21.7.7

Virtual Python Environment builder

  • latest version

    21.14.5

  • latest non vulnerable version

  • first published

    19 years ago

  • latest version published

    3 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the virtualenv package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Command Injection

    Affected versions of this package are vulnerable to Command Injection via the BatchActivator.quote method in src/virtualenv/activation/batch/__init__.py, which previously returned its input string unchanged. When a virtualenv is created in a path containing cmd.exe operator characters such as &, |, <, >, ^, !, or ", those characters are embedded verbatim into the generated activate.bat script inside @set "VAR=value" statements. An attacker who controls the virtualenv path or environment values can inject arbitrary cmd.exe commands that execute when a user sources the activation script.

    How to fix Command Injection?

    Upgrade virtualenv to version 21.7.12 or higher.

    [,21.7.12)
    • M
    CRLF Injection

    Affected versions of this package are vulnerable to CRLF Injection via the PyEnvCfg.write method in src/virtualenv/create/pyenv_cfg.py, where configuration values containing line boundary characters (such as \n, \r, \v, \f, and Unicode line/paragraph separators) are written into pyvenv.cfg without sanitization. An attacker who controls a value written to pyvenv.cfg - for example, the virtual environment prompt - can inject additional configuration keys into the file, which are then read back as legitimate entries and can override critical settings such as home.

    How to fix CRLF Injection?

    Upgrade virtualenv to version 21.7.11 or higher.

    [,21.7.11)
    • H
    Resources Downloaded over Insecure Protocol

    Affected versions of this package are vulnerable to Resources Downloaded over Insecure Protocol via the download_wheel function in src/virtualenv/seed/wheels/acquire.py, which invokes pip download to fetch seed wheels without subsequently verifying the downloaded wheel's SHA-256 digest against the PyPI JSON API. An attacker positioned between the client and the package index can serve a tampered wheel that pip accepts, and because no digest check is performed, the malicious wheel is silently used to seed new virtual environments, leading to full compromise of the seeded environment's integrity and confidentiality.

    Note: This is only exploitable when the default PyPI index is in use and an attacker can intercept or manipulate the download (e.g. via a MitM or a compromised mirror).

    How to fix Resources Downloaded over Insecure Protocol?

    Upgrade virtualenv to version 21.7.12 or higher.

    [,21.7.12)
    • H
    Command Injection

    Affected versions of this package are vulnerable to Command Injection via path interpolation in the generated activate.sh (bash) and activate.fish (fish) activation scripts. When a virtualenv is created with a path containing shell metacharacters, those characters are embedded unquoted into the activation script, allowing an attacker who controls the virtualenv path to inject arbitrary shell commands that execute when a user sources the activation script.

    How to fix Command Injection?

    Upgrade virtualenv to version 21.7.13 or higher.

    [,21.7.13)