Disputed by NVD and pip upstream. The CVE describes pip's --extra-index-url
behavior where the highest version number is installed regardless of which
index it comes from. The pip team considers this intended functionality, not
a security flaw. Red Hat closed as WONTFIX; Ubuntu priority: Negligible.
Affects all pip versions with no fix planned.