virtualenv is vulnerable to Download of Code Without Integrity Check
37
Low Risk
virtualenv's download_wheel() runs pip download for the periodic seed-wheel update and the --download flag and hands the returned wheel straight to the seeder without checking its bytes. A compromised index, a stale mirror, or an intercepted download can substitute a different wheel under the same distribution, version, and filename, and virtualenv caches and seeds that wheel into every environment created afterward with no warning. The fix computes the downloaded wheel's sha256 and compares it against the digest PyPI's public JSON API reports for that release, skipping the check only when a custom index is configured.
You are affected if you are using a version that falls within the vulnerable range and you rely on virtualenv's periodic seed-wheel update or the --download flag against a package index that could be compromised, stale, or subject to an intercepted (MITM'd) connection.
virtualenv is vulnerable to Download of Code Without Integrity Check in versions 0.0.1 - 21.7.11.
Upgrade the virtualenv library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.