Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g3p5-fjj9-h8gj

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.3
CVSS3: 8.4

Описание

Improper Input Validation in pip

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.

Пакеты

Наименование

pip

pip
Затронутые версииВерсия исправления

< 1.3

1.3

EPSS

Процентиль: 97%
0.39922
Средний

7.3 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 12 лет назад

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.

nvd
больше 12 лет назад

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.

debian
больше 12 лет назад

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository ...

EPSS

Процентиль: 97%
0.39922
Средний

7.3 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-20