Lucene search

K
osvGoogleOSV:GHSA-GPVV-69J7-GWJ8
HistoryJun 09, 2021 - 5:35 p.m.

Path Traversal in pip

2021-06-0917:35:04
Google
osv.dev
23

0.003 Low

EPSS

Percentile

65.5%

The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have …/ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py. A fix was committed 6704f2ace.

Rows per page:
1-10 of 761