[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2022-1742 --- python-pip

ID: oval:org.secpod.oval:def:1700797Date: (C)2022-02-01   (M)2023-11-13
Class: PATCHFamily: unix




A flaw was found in python-urllib3. SSL certificate validation is omitted in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted. A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity

Platform:
Amazon Linux 2
Product:
python-pip
python2-pip
python3-pip
Reference:
ALAS2-2022-1742
CVE-2021-28363
CVE-2021-3572
CVE    2
CVE-2021-28363
CVE-2021-3572
CPE    4
cpe:/a:python:python3-pip
cpe:/a:python:python2-pip
cpe:/o:amazon:linux:2
cpe:/a:python:python-pip
...

© SecPod Technologies