Description
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2370-1 | python-pip security update |
Github GHSA |
GHSA-gpvv-69j7-gwj8 | Path Traversal in pip |
Ubuntu USN |
USN-4601-1 | pip vulnerability |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Opensuse
Subscribe
Leap
Subscribe
Oracle
Subscribe
Communications Cloud Native Core Network Function Cloud Native Environment
Subscribe
Communications Cloud Native Core Policy
Subscribe
Pypa
Subscribe
Pip
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Software Collections
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T03:00:17.373Z
Reserved: 2020-09-04T00:00:00.000Z
Link: CVE-2019-20916
No data.
Status : Modified
Published: 2020-09-04T20:15:11.013
Modified: 2024-11-21T04:39:40.913
Link: CVE-2019-20916
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Github GHSA
Ubuntu USN