In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| portage(PyPI) | 0 | 3.0.47 | N/A |
CVSS Metrics