[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2021-1639 --- python-pip, python2-pip, python3-pip

ID: oval:org.secpod.oval:def:1700622Date: (C)2021-05-31   (M)2024-02-15
Class: PATCHFamily: unix




The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py

Platform:
Amazon Linux 2
Product:
python-pip
python2-pip
python3-pip
Reference:
ALAS2-2021-1639
CVE-2019-20916
CVE    1
CVE-2019-20916

© SecPod Technologies