Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3572

Опубликовано: 24 апр. 2021
Источник: redhat
CVSS3: 4.5

Описание

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity.

Отчет

This flaw has been rated as having a security impact of Low. To exploit this flaw, the attacker needs access to the repository to create a specially crafted tag and force a different revision to be installed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7python-pipOut of support scope
Red Hat Enterprise Linux 7python-virtualenvOut of support scope
Red Hat Enterprise Linux 8gimp:flatpak/python2-pipNot affected
Red Hat Enterprise Linux 8inkscape:flatpak/python2-pipFix deferred
Red Hat Enterprise Linux 8python27:2.7/python2-pipNot affected
Red Hat Enterprise Linux 9python-pipAffected
Red Hat Software Collectionspython27-python-pipNot affected
Red Hat Software Collectionspython27-python-virtualenvNot affected
Red Hat Enterprise Linux 8python39FixedRHSA-2021:416009.11.2021
Red Hat Enterprise Linux 8python39-develFixedRHSA-2021:416009.11.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1962856python-pip: Incorrect handling of unicode separators in git references

4.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
ubuntu
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 5.7
nvd
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 5.7
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 5.7
debian
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separator ...

suse-cvrf
около 3 лет назад

Security update for python3

4.5 Medium

CVSS3