/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2021-3572

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2021-3572

CGA ID

CGA-2pg9-jhcf-r8c4

Severity

5.7

Medium

CVSS V3

Description

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images