Lucene search

K
redosRedosROS-20230619-05
HistoryJun 19, 2023 - 12:00 a.m.

ROS-20230619-05

2023-06-1900:00:00
redos.red-soft.ru
43
python programming language
pip module
policy component
oracle communications cloud native core policy
vulnerability
input validation
directory path
software installation
data integrity
remote attack

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.004

Percentile

73.8%

A vulnerability in the pip module of the Python programming language is related to incorrect input validation in the
Policy component (python-pip) in Oracle Communications Cloud Native Core Policy. Exploitation
The vulnerability could allow an attacker acting remotely to manipulate data.

The vulnerability in the pip module of the Python programming language is related to a flaw in limiting the path name of the
directory path name when specified in the URL for software installation. Exploitation of the vulnerability could
Allow an attacker acting remotely to affect data integrity

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64python3-pip< 19.1.1-3UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS

0.004

Percentile

73.8%