A Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection. Reference: https://snyk.io/vuln/SNYK-PYTHON-COOKIECUTTER-2414281 https://github.com/cookiecutter/cookiecutter/commit/fdffddb31fd2b46344dfa317531ff155e7999f77 https://github.com/cookiecutter/cookiecutter/releases/tag/2.1.1
Created python-cookiecutter tracking bugs for this issue: Affects: fedora-all [bug 2095734]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.