CyberRota Analysis
AI-GeneratedPrior to version 21.7.12, virtualenv is vulnerable to a flaw in the download_wheel() function, which allows for the acceptance of unverified pip and setuptools wheels, potentially enabling an attacker to inject malicious code into Python environments through compromised package indices or intercepted connections. This vulnerability poses a significant risk to developers and organizations relying on virtualenv for creating isolated environments, as it can lead to the execution of untrusted code. Users of virtualenv, especially those utilizing custom package indices, should prioritize upgrading to the patched version to mitigate this security risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
virtualenv is a tool for creating isolated virtual python environments. Prior to 21.7.12, download_wheel() accepts pip and setuptools seed wheels fetched for periodic updates or the --download option without checking their bytes against an authoritative digest equivalent to the embedded wheels' BUNDLE_SHA256 verification. A compromised index, stale mirror, or intercepted TLS connection can substitute a different wheel under the requested distribution, version, and filename, after which virtualenv caches and seeds the attacker-controlled wheel into subsequently created environments. The verification applies to the default PyPI path and is intentionally skipped when PIP_INDEX_URL, PIP_EXTRA_INDEX_URL, or PIP_INDEX configures a custom index that may legitimately publish rebuilt wheels. This issue is fixed in version 21.7.12.