• CVE-2021-3572

发布时间: 2021年7月31日

修改时间: 2024年10月31日

概要

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity.

CVSS v3 指标

NVD openEuler
Confidentiality None None
Attack Vector Network Network
CVSS评分 5.7 4.5
Attack Complexity Low Low
Privileges Required Low High
Scope Unchanged Unchanged
Integrity High High
User Interaction Required Required
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2021-1283 python-pip security update 2021年7月31日

影响产品

产品 状态
KY3.4-4A python-pip Fixed