PT-2021-21809 · Unknown · Refined Theme+2

Published

2021-11-30

·

Updated

2021-12-01

·

CVE-2021-3769

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions pygmalion theme (affected versions not specified) pygmalion-virtualenv theme (affected versions not specified) refined theme (affected versions not specified)
Description The vulnerability exists in the pygmalion, pygmalion-virtualenv, and refined themes. These themes use print -P on user-supplied strings to print them to the terminal, specifically on git information such as the branch name. If the branch has a specially-crafted name, the vulnerability can be exploited.
Recommendations For the pygmalion theme, consider disabling the use of print -P on user-supplied strings until a patch is available. For the pygmalion-virtualenv theme, consider disabling the use of print -P on user-supplied strings until a patch is available. For the refined theme, consider disabling the use of print -P on user-supplied strings until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3769

Affected Products

Pygmalion Theme
Pygmalion-Virtualenv Theme
Refined Theme