Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xp3-jfq3-5q8x

Опубликовано: 15 нояб. 2021
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 5.7

Описание

Improper Input Validation in pip

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

Пакеты

Наименование

pip

pip
Затронутые версииВерсия исправления

< 21.1

21.1

EPSS

Процентиль: 47%
0.0024
Низкий

7.1 High

CVSS4

5.7 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 5.7
ubuntu
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 4.5
redhat
около 4 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 5.7
nvd
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 5.7
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 5.7
debian
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separator ...

EPSS

Процентиль: 47%
0.0024
Низкий

7.1 High

CVSS4

5.7 Medium

CVSS3

Дефекты

CWE-20