Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-3572

Опубликовано: 10 нояб. 2021
Источник: ubuntu
Приоритет: low
CVSS2: 3.5
CVSS3: 5.7

Описание

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

20.3.4-4
esm-apps/bionic

released

9.0.1-2.3~ubuntu1.18.04.8+esm1
esm-apps/focal

not-affected

20.0.2-5ubuntu1.5
esm-apps/jammy

not-affected

20.3.4-4
esm-apps/xenial

released

8.1.1-2ubuntu0.6+esm2
esm-infra-legacy/trusty

not-affected

8.1.1-2ubuntu0.6+esm2
focal

not-affected

20.0.2-5ubuntu1.5
groovy

ignored

end of life
hirsute

ignored

end of life

Показывать по

3.5 Low

CVSS2

5.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.5
redhat
около 4 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 5.7
nvd
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 5.7
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 5.7
debian
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separator ...

suse-cvrf
около 3 лет назад

Security update for python3

3.5 Low

CVSS2

5.7 Medium

CVSS3