Amazon Linux 2023 Security Advisory: ALAS-2025-831
Advisory Release Date: 2025-01-30 03:53 Pacific
Advisory Updated Date: 2025-02-05 11:08 Pacific
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287. (CVE-2024-53899)
Affected Packages:
python-virtualenv
Issue Correction:
Run dnf update python-virtualenv --releasever 2023.6.20250203 to update your system.
noarch:
python3-virtualenv-20.4.0-3.amzn2023.0.4.noarch
src:
python-virtualenv-20.4.0-3.amzn2023.0.4.src