/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-57rv-3w6v-vfm6

Published

Last updated

https://images.chainguard.dev/security/CGA-57rv-3w6v-vfm6
Package

py3-pip

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2024-47081
  • GHSA-9hjg-9r4m-mvj7

Severity

5.3

Medium

CVSS V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2024-47081

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

CVE-2024-47081 is patched via py3-pip/fix-CVE-2024-47081.patch. The scanner detects requests 2.32.3 in vendor.txt, but the actual vulnerability (using ri.netloc instead of ri.hostname) has been fixed. The patched code uses ri.hostname for netrc lookups, preventing credential leakage.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing