The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
2019-11-05T22:15:10.813
2024-11-21T01:57:03.813
Modified
CVSSv3.1: 5.9 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pypa | pip | < 1.5 | Yes |
Application | virtualenv | virtualenv | 12.0.7 | Yes |
Operating System | fedoraproject | fedora | 20 | Yes |
Operating System | fedoraproject | fedora | 21 | Yes |
Application | redhat | openshift | 1.0 | Yes |
Application | redhat | openshift | 2.0 | Yes |
Application | redhat | software_collections | - | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |