All errata/c10f2/ALT-PU-2025-10403-3
ALT-PU-2025-10403-3

Package update python3-module-pip in branch c10f2

Version23.3.2-alt1
Published2025-08-15
Max severityMEDIUM
Severity:

Closed issues (2)

BDU:2023-08026
MEDIUM5.5

Уязвимость модуля pip языка программирования Python, связанная с непринятием мер по чистке данных на управляющем уровне, позволяющая нарушителю изменить конфигурацию репозитория

Published: 2023-11-22Modified: 2026-02-10
CVSS 3.xMEDIUM 5.5
CVSS:3.x/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.0MEDIUM 4.6
CVSS:2.0/AV:L/AC:L/Au:S/C:N/I:C/A:N
References
CVE-2023-5752
LOW3.3

When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.

Published: 2023-10-25Modified: 2025-11-03
CVSS 3.xLOW 3.3
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
References