Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:32902
HistoryNov 11, 2021 - 4:14 a.m.

Improper Input Validation

2021-11-1104:14:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

0.001 Low

EPSS

Percentile

28.1%

pip suffers from improper input validation. The library does not properly handle unicode separators in git references. An attacker can use this flaw to install a different revision on a repository.

CPENameOperatorVersion
piple21.0.1
piple21.0.1