Lucene search

K
cveMitreCVE-2013-1629
HistoryAug 06, 2013 - 2:52 a.m.

CVE-2013-1629

2013-08-0602:52:10
CWE-20
mitre
web.nvd.nist.gov
62
2
cve-2013-1629
pip
pypi
repository
integrity checks
man-in-the-middle
arbitrary code

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.004

Percentile

73.0%

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a “pip install” operation.

Affected configurations

Nvd
Node
pypapipRange<1.3
VendorProductVersionCPE
pypapip*cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:*

Social References

More

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

Low

EPSS

0.004

Percentile

73.0%