Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Directory Traversal. The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.
Remediation
There is no fixed version for python-pip
.
References
CVSS Score
7.5
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityHigh
-
AvailabilityNone
- CVE
- CVE-2019-20916
- CWE
- CWE-22
- Snyk ID
- SNYK-DEBIAN10-PYTHONPIP-609805
- Disclosed
- 04 Sep, 2020
- Published
- 05 Sep, 2020