BIT-pip-2021-3572

Import Source
https://github.com/bitnami/vulndb/tree/main/data/pip/BIT-pip-2021-3572.json
Aliases
Published
2024-03-06T11:01:55.978Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

References

Affected packages

Bitnami / pip

Package

Name
pip

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
21.1.0