CVE-2021-3572 describes a medium-severity vulnerability in python-pip, specifically affecting versions prior to 21.1, as well as various Oracle and PyPA products that utilize pip. This flaw allows a remote attacker to potentially install an incorrect revision from a git repository due to improper handling of Unicode separators in git references, primarily impacting data integrity. The attack requires user interaction and low privileges, but its complexity is low. There is no evidence of active exploitation, public exploit code, or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 21.1CPE matchmatch criteria | cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:* | ||
9.3.6CPE matchmatch criteria | cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:* | ||
1.10.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:* | ||
22.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:22.1.0:*:*:*:*:*:*:* | ||
1.15.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-3572
Apr 12, 2022Improper Input Validation in pip
Nov 15, 2021A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
Nov 9, 2021python-pip: Incorrect handling of unicode separators in git references
Apr 24, 2021