VDB

ALINUX2-SA-2022%3A0030

ALINUX2-SA-2022%3A0030 PUBLISHED CVSS 8 HIGH

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2019-20916: The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.

Risk Scores

CVSS 3.1
8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Alibaba Cloudpython-virtualenv

Timeline

  • Jul 4, 2022 CVE Published
  • Jul 4, 2022 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›