Lucene search

K
githubGitHub Advisory DatabaseGHSA-4GV5-QHVR-36VV
HistoryMay 13, 2022 - 1:11 a.m.

Improper Link Resolution Before File Access in pip

2022-05-1301:11:25
CWE-59
GitHub Advisory Database
github.com
12
pip
symlink attack
file access

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

EPSS

0

Percentile

5.1%

pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.

Affected configurations

Vulners
Node
pypapipRange<1.3
VendorProductVersionCPE
pypapip*cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

EPSS

0

Percentile

5.1%