Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-20225

Опубликовано: 08 мая 2020
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 6.8
CVSS3: 7.8

Описание

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely

РелизСтатусПримечание
bionic

ignored

devel

ignored

eoan

ignored

end of life
esm-apps-legacy/xenial

ignored

esm-apps/bionic

ignored

esm-apps/focal

ignored

esm-apps/xenial

ignored

esm-infra-legacy/trusty

ignored

focal

ignored

precise/esm

DNE

Показывать по

EPSS

Процентиль: 75%
0.01736
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
больше 6 лет назад

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely

CVSS3: 7.8
nvd
около 6 лет назад

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely

CVSS3: 7.8
msrc
10 месяцев назад

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely

CVSS3: 7.8
debian
около 6 лет назад

An issue was discovered in pip (all versions) because it installs the ...

github
около 4 лет назад

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number).

EPSS

Процентиль: 75%
0.01736
Низкий

6.8 Medium

CVSS2

7.8 High

CVSS3