« List of all CVEs

CVE-2021-3572

Published: 11/10/2021 Last updated: 8/3/2024 Reserved: 6/1/2021

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

catala

Products affected (1)

Product Vendor Version
python-pip n/a n/a

References (8)