CVE-2021-3572
בינונית 5.7
תיאור (מקור, אנגלית)
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
מדדים
- CVSS 3.1
-
5.7 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N - EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-7/10/2026
- CWE
- CWE-20
מוצרים מושפעים
pypa: pip; oracle: agile product lifecycle management; oracle: communications cloud native core network function cloud native environment; oracle: communications cloud native core policy
קישורים
- https://bugzilla.redhat.com/show_bug.cgi?id=1962856 Issue TrackingPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1962856 Issue TrackingPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://security.netapp.com/advisory/ntap-20240621-0006/