Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-5123

Опубликовано: 31 июл. 2013
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1python-virtualenvWill not fix
Red Hat OpenShift Enterprise 2python27-python-pipWill not fix
Red Hat OpenShift Enterprise 2python-virtualenvWill not fix
Red Hat Software Collectionspython27-python-virtualenvAffected
Red Hat Software Collectionspython33-python-virtualenvAffected

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1066692python-pip: insecure software download with mirroring support

EPSS

Процентиль: 94%
0.12381
Средний

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 6 лет назад

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

CVSS3: 5.9
nvd
больше 6 лет назад

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

CVSS3: 5.9
debian
больше 6 лет назад

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 use ...

CVSS3: 5.9
github
больше 3 лет назад

Improper Authentication in pip

suse-cvrf
больше 6 лет назад

Recommended update for python-jmespath, python-jsonschema, python-paramiko, python-pexpect, python-pip, python-ply, python-pretend, python-process-tests, python-pycodestyle, python-pyflakes, python-pyxdg, python-tabulate, python-vcversioner

EPSS

Процентиль: 94%
0.12381
Средний

4.3 Medium

CVSS2