Skip to content

pex 2.1.103 uses pip 20.3.4; pip 20.3.4 has vulnerability CVE-2021-3572 #1877

@hpatelbitglass

Description

@hpatelbitglass

More info regarding the vulnerability can be found at: https://avd.aquasec.com/nvd/2021/cve-2021-3572/
Fixed pip version 21.1
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions