CVE-2021-3572

⚪ Do wiadomości

Błąd w python-pip umożliwia atakującemu instalację innej wersji repozytorium.

CVSS: źródło nieustalone · szczegóły: D1

CVSS
5.7
EPSS
1.8%
Exploit
none
Vendor
oracle
Opis źródłowy (NVD)

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

brak Status patcha: nieustalony
Źródła i daty
ŹródłoWartość
NVD – CVSS 5.7
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS · ocena nieustalona1.8%
Opublikowano (NVD)2021-11-10 18:15:09 UTC
Ostatnia modyfikacja (NVD)2026-10-08 21:17:40 UTC
Referencje