QID 996780
Date Published: 2024-01-23
QID 996780: Python (Pip) Security Update for virtualenv (GHSA-3jhc-wjqf-5f2c)
virtualenv.py in virtualenv before 1.5 allows local users to overwrite arbitrary files via a symlink attack on a certain file in /tmp/.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-3jhc-wjqf-5f2c for updates and patch information.
Vendor References
- GHSA-3jhc-wjqf-5f2c -
github.com/advisories/GHSA-3jhc-wjqf-5f2c
CVEs related to QID 996780
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3jhc-wjqf-5f2c | virtualenv |
|