Safety vulnerability ID: 42559
The information on this page was manually curated by our Cybersecurity Intelligence Team.
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity.
Latest version: 24.3.1
The PyPA recommended tool for installing Python packages.
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1. See CVE-2021-3572.
MISC:https://bugzilla.redhat.com/show_bug.cgi?id=1962856: https://bugzilla.redhat.com/show_bug.cgi?id=1962856
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application