Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f594-f3v3-g649

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.2

Описание

pyshop vulnerable to man-in-the-middle attacks due to using HTTP to retrieve packages from the PyPI repository

pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.

Пакеты

Наименование

pyshop

pip
Затронутые версииВерсия исправления

< 0.7.1

0.7.1

EPSS

Процентиль: 67%
0.00531
Низкий

8.2 High

CVSS4

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 12 лет назад

pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.

EPSS

Процентиль: 67%
0.00531
Низкий

8.2 High

CVSS4

Дефекты

CWE-20