pypa kayıtları
pypa üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %90,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-287 Improper Authentication1
- CWE-36 Absolute Path Traversal1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2022-21668Kavram kanıtı | Pipenv's requirements.txt parsing allows malicious index url in commentspypa · pipenv · CWE-20 | Yüksek8,6 | — | %3,9 | 10 Oca 2022 |
32İzleyin | CVE-2018-20225Kavram kanıtı | An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intendedpypa · pip · CWE-20 | Yüksek7,8 | — | %1,8 | 8 May 2020 |
31İzleyin | CVE-2019-20916İstismar yok | The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition hpypa · pip · CWE-22 | Yüksek7,5 | — | %3,0 | 4 Eyl 2020 |
29İzleyin | CVE-2013-1629İstismar yok | pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allpypa · pip · CWE-20 | Orta6,8 | — | %6,2 | 5 Ağu 2013 |
25İzleyin | CVE-2013-5123Kavram kanıtı | The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackerspypa · pip · CWE-287 | Orta5,9 | — | %8,0 | 5 Kas 2019 |
23İzleyin | CVE-2021-3572Kavram kanıtı | A flaw was found in python-pip in the way it handled Unicode separators in git references.pypa · pip · CWE-20 | Orta5,7 | — | %1,8 | 10 Kas 2021 |
22İzleyin | CVE-2026-13346İstismar yok | pip absolute path traversal during download from malicious package indexespypa · pip · CWE-36 | Orta5,6 | — | %0,3 | 29 Tem 2026 |
16İzleyin | CVE-2026-8643İstismar yok | pip can extract console_scripts and gui_scripts outside installation directorypypa · pip · CWE-22 | Orta4,1 | — | %0,5 | 1 Haz 2026 |
13İzleyin | CVE-2023-5752İstismar yok | Mercurial configuration injectable in repo revision when installing via pippypa · pip · CWE-77 | Düşük3,3 | — | %0,5 | 25 Eki 2023 |
8İzleyin | CVE-2014-8991İstismar yok | pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* fipypa · pip | Düşük2,1 | — | %0,4 | 24 Kas 2014 |
8İzleyin | CVE-2013-1888İstismar yok | pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.pypa · pip · CWE-59 | Düşük2,1 | — | %0,4 | 17 Ağu 2013 |
- CVE-2022-2166835İzleyin
Pipenv's requirements.txt parsing allows malicious index url in comments
YüksekCVSS 8,6Kavram kanıtıEPSS %4pypa · pipenv10 Oca 2022
- CVE-2018-2022532İzleyin
An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended
YüksekCVSS 7,8Kavram kanıtıEPSS %2pypa · pip8 May 2020
- CVE-2019-2091631İzleyin
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition h
YüksekCVSS 7,5İstismar yokEPSS %3pypa · pip4 Eyl 2020
- CVE-2013-162929İzleyin
pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which all
OrtaCVSS 6,8İstismar yokEPSS %6pypa · pip5 Ağu 2013
- CVE-2013-512325İzleyin
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers
OrtaCVSS 5,9Kavram kanıtıEPSS %8pypa · pip5 Kas 2019
- CVE-2021-357223İzleyin
A flaw was found in python-pip in the way it handled Unicode separators in git references.
OrtaCVSS 5,7Kavram kanıtıEPSS %2pypa · pip10 Kas 2021
- CVE-2026-1334622İzleyin
pip absolute path traversal during download from malicious package indexes
OrtaCVSS 5,6İstismar yokEPSS %0pypa · pip29 Tem 2026
- CVE-2026-864316İzleyin
pip can extract console_scripts and gui_scripts outside installation directory
OrtaCVSS 4,1İstismar yokEPSS %0pypa · pip1 Haz 2026
- CVE-2023-575213İzleyin
Mercurial configuration injectable in repo revision when installing via pip
DüşükCVSS 3,3İstismar yokEPSS %0pypa · pip25 Eki 2023
- CVE-2014-89918İzleyin
pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* fi
DüşükCVSS 2,1İstismar yokEPSS %0pypa · pip24 Kas 2014
- CVE-2013-18888İzleyin
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
DüşükCVSS 2,1İstismar yokEPSS %0pypa · pip17 Ağu 2013