ALT-PU-2021-1772-1
Package python3-module-pip updated to version 21.1.1-alt1 for branch sisyphus in task 271297.
Closed vulnerabilities
BDU:2023-03310
Уязвимость модуля pip языка программирования Python, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю оказать воздействие на целостность данных
Modified: 2024-11-21
CVE-2021-28363
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.
- https://github.com/urllib3/urllib3/commit/8d65ea1ecf6e2cdc27d42124e587c1b83a3118b0
- https://github.com/urllib3/urllib3/commit/8d65ea1ecf6e2cdc27d42124e587c1b83a3118b0
- https://github.com/urllib3/urllib3/commits/main
- https://github.com/urllib3/urllib3/commits/main
- https://github.com/urllib3/urllib3/security/advisories/GHSA-5phf-pp7p-vc2r
- https://github.com/urllib3/urllib3/security/advisories/GHSA-5phf-pp7p-vc2r
- FEDORA-2021-3f378dda90
- FEDORA-2021-3f378dda90
- https://pypi.org/project/urllib3/1.26.4/
- https://pypi.org/project/urllib3/1.26.4/
- GLSA-202107-36
- GLSA-202107-36
- GLSA-202305-02
- GLSA-202305-02
- https://security.netapp.com/advisory/ntap-20240621-0007/
- https://security.netapp.com/advisory/ntap-20240621-0007/
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
Modified: 2024-11-21
CVE-2021-3572
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
- https://bugzilla.redhat.com/show_bug.cgi?id=1962856
- https://bugzilla.redhat.com/show_bug.cgi?id=1962856
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html
- https://www.oracle.com/security-alerts/cpujul2022.html