Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c5h8-cq4v-cvfm

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.2
CVSS3: 5.9

Описание

Improper Authentication in pip

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

Пакеты

Наименование

pip

pip
Затронутые версииВерсия исправления

< 1.5

1.5

EPSS

Процентиль: 94%
0.12381
Средний

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 6 лет назад

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

redhat
больше 12 лет назад

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

CVSS3: 5.9
nvd
больше 6 лет назад

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

CVSS3: 5.9
debian
больше 6 лет назад

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 use ...

suse-cvrf
больше 6 лет назад

Recommended update for python-jmespath, python-jsonschema, python-paramiko, python-pexpect, python-pip, python-ply, python-pretend, python-process-tests, python-pycodestyle, python-pyflakes, python-pyxdg, python-tabulate, python-vcversioner

EPSS

Процентиль: 94%
0.12381
Средний

8.2 High

CVSS4

5.9 Medium

CVSS3

Дефекты

CWE-287