virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:10953 https://access.redhat.com/errata/RHSA-2024:10953
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2024:11048 https://access.redhat.com/errata/RHSA-2024:11048
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2024:11091 https://access.redhat.com/errata/RHSA-2024:11091
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:11093 https://access.redhat.com/errata/RHSA-2024:11093
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2024:11094 https://access.redhat.com/errata/RHSA-2024:11094
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2025:0002 https://access.redhat.com/errata/RHSA-2025:0002