Описание
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | |
| bionic | not-affected | |
| devel | not-affected | |
| esm-apps-legacy/xenial | not-affected | 8.1.1-2ubuntu0.4 |
| esm-apps/bionic | not-affected | |
| esm-apps/xenial | not-affected | 8.1.1-2ubuntu0.4 |
| esm-infra-legacy/trusty | not-affected | 1.5.4-1ubuntu4 |
| lucid | ignored | end of life, was deferred |
| precise | ignored | end of life |
| precise/esm | DNE | precise was deferred [2013-08-22] |
Показывать по
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3
Связанные уязвимости
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 use ...
Recommended update for python-jmespath, python-jsonschema, python-paramiko, python-pexpect, python-pip, python-ply, python-pretend, python-process-tests, python-pycodestyle, python-pyflakes, python-pyxdg, python-tabulate, python-vcversioner
EPSS
4.3 Medium
CVSS2
5.9 Medium
CVSS3