Lucene search

K
osvGoogleOSV:GHSA-4GV5-QHVR-36VV
HistoryMay 13, 2022 - 1:11 a.m.

Improper Link Resolution Before File Access in pip

2022-05-1301:11:25
Google
osv.dev
15
pip
improper link resolution
file access
symlink attack
temporary directory
software

EPSS

0

Percentile

5.1%

pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.