GHSA-g3p5-fjj9-h8gj

Suggest an improvement
Source
https://github.com/advisories/GHSA-g3p5-fjj9-h8gj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-g3p5-fjj9-h8gj/GHSA-g3p5-fjj9-h8gj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g3p5-fjj9-h8gj
Aliases
Published
2022-05-13T01:11:25Z
Modified
2024-10-09T21:37:11Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 7.3 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Improper Input Validation in pip
Details

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.

Database specific
{
    "cwe_ids":  [
        "CWE-20"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-07-08T19:00:03Z",
    "nvd_published_at":  "2013-08-06T02:52:00Z",
    "severity":  "HIGH"
}
References

Affected packages

PyPI / pip

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3

Affected versions

0.*
0.2
0.2.1
0.3
0.3.1
0.4
0.5
0.5.1
0.6
0.6.1
0.6.2
0.6.3
0.7
0.7.1
0.7.2
0.8
0.8.1
0.8.2
0.8.3
1.*
1.0
1.0.1
1.0.2
1.1
1.2
1.2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-g3p5-fjj9-h8gj/GHSA-g3p5-fjj9-h8gj.json"