Description
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0186 | A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1. |
Github GHSA |
GHSA-5xp3-jfq3-5q8x | Improper Input Validation in pip |
Ubuntu USN |
USN-4961-2 | pip vulnerability |
References
History
Tue, 25 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oracle agile Product Lifecycle Management
|
|
| CPEs | cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle agile Plm
|
Oracle agile Product Lifecycle Management
|
Subscriptions
Oracle
Subscribe
Agile Product Lifecycle Management
Subscribe
Communications Cloud Native Core Network Function Cloud Native Environment
Subscribe
Communications Cloud Native Core Policy
Subscribe
Pypa
Subscribe
Pip
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Rhel Software Collections
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:01:08.109Z
Reserved: 2021-06-01T00:00:00.000Z
Link: CVE-2021-3572
No data.
Status : Modified
Published: 2021-11-10T18:15:09.510
Modified: 2026-08-25T16:28:27.310
Link: CVE-2021-3572
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-20
Improper Input Validation
- NVD-CWE-noinfo
EUVD
Github GHSA
Ubuntu USN