CVE-2023-5752

Source
https://cve.org/CVERecord?id=CVE-2023-5752
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5752.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-5752
Aliases
Downstream
AZL (2)
CGA (8)
CLSA (1)
DEBIAN (1)
ECHO (1)
MGASA (1)
MINI (1)
OESA (2)
openSUSE (1)
RHSA (1)
ROOT (1)
SUSE (4)
UBUNTU (1)
Related
Published
2023-10-24T20:56:05Z
Modified
2026-08-12T03:51:16Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Mercurial configuration injectable in repo revision when installing via pip
Details

When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.

Database specific
{
    "cna_assigner":  "PSF",
    "cwe_ids":  [
        "CWE-77"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5752.json"
}
References

Affected packages

Git / github.com/pypa/pip

Affected ranges

Type
GIT
Repo
https://github.com/pypa/pip
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "23.3"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

0.*
0.3
0.6
0.7
0.7.1
0.8
0.8.2
0.8.3
1.*
1.0
1.2
1.4rc1
1.4rc2
10.*
10.0.0
10.0.1
18.*
18.0
18.1
19.*
19.0
19.0.2
19.1.1
20.*
20.0.2
21.*
21.0
21.3
6.*
6.0
9.*
9.0.0
9.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5752.json"