{"id":"PYSEC-2024-10","details":"In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.","aliases":["CVE-2016-20021","GHSA-pw5x-x5jw-ccmh"],"modified":"2026-06-10T17:01:37.021402273Z","published":"2024-01-12T03:15:00Z","references":[{"type":"WEB","url":"https://wiki.gentoo.org/wiki/Portage"},{"type":"WEB","url":"https://gitweb.gentoo.org/proj/portage.git/tree/NEWS"},{"type":"REPORT","url":"https://bugs.gentoo.org/597800"},{"type":"FIX","url":"https://bugs.gentoo.org/597800"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-pw5x-x5jw-ccmh"}],"affected":[{"package":{"name":"portage","ecosystem":"PyPI","purl":"pkg:pypi/portage"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.47"}]}],"versions":["3.0.18","3.0.19","3.0.20","3.0.21","3.0.22","3.0.23","3.0.24","3.0.25","3.0.26","3.0.27","3.0.28","3.0.29","3.0.30","3.0.31","3.0.32","3.0.33","3.0.34","3.0.35","3.0.36","3.0.37","3.0.38","3.0.38.1","3.0.39","3.0.40","3.0.41","3.0.42","3.0.43","3.0.44","3.0.45","3.0.45.1","3.0.45.2","3.0.45.3","3.0.46"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/portage/PYSEC-2024-10.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}