Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3572

Опубликовано: 10 нояб. 2021
Источник: debian
EPSS Низкий

Описание

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-pipfixed20.3.4-2package
python-pipno-dsabusterpackage
python-pippostponedstretchpackage

Примечания

  • https://bugs.launchpad.net/ubuntu/+source/python-pip/+bug/1926957

  • https://github.com/pypa/pip/pull/9827

  • https://github.com/pypa/pip/commit/ca832b2836e0bffa7cf95589acdcd71230f5834e (21.1)

EPSS

Процентиль: 47%
0.0024
Низкий

Связанные уязвимости

CVSS3: 5.7
ubuntu
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 4.5
redhat
около 4 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 5.7
nvd
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 5.7
msrc
около 3 лет назад

Описание отсутствует

suse-cvrf
около 3 лет назад

Security update for python3

EPSS

Процентиль: 47%
0.0024
Низкий