QID 980106

QID 980106: Python (pip) Security Update for pip (GHSA-5xp3-jfq3-5q8x)

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.7 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Customers are advised to refer to GHSA-5xp3-jfq3-5q8x for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980106

    Software Advisories
    Advisory ID Software Component Link
    GHSA-5xp3-jfq3-5q8x pip URL Logo github.com/advisories/GHSA-5xp3-jfq3-5q8x