VDB
BDU%3A2023-08026
BDU%3A2023-08026
PUBLISHED
CVSS 4.599999904632568 MEDIUM
Уязвимость модуля pip языка программирования Python, связанная с непринятием мер по чистке данных на управляющем уровне, позволяющая нарушителю изменить конфигурацию репозитория
Risk Scores
CVSS 2.0
4.599999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», Fedora Project, Python Software Foundation, Google Inc | Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise High Performance Computing, Red Hat Quay, SUSE Linux Enterprise Module for Basesystem, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Red Hat Enterprise Linux, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise Module for Public Cloud, Fedora, Red Hat Ansible Automation Platform, Red Hat OpenShift Dev Spaces, Python-pip, Suse Linux Enterprise Desktop, OpenSUSE Leap, SUSE Linux Enterprise Module for Python 3, Android Studio |
Timeline
- Nov 22, 2023 CVE Published
- Feb 10, 2026 CVE Updated
References
- https://github.com/pypa/pip/pull/12306 url
- https://mail.python.org/archives/list/security-announce@python.org/thread/F4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL/ url
- https://vuldb.com/?id.243289 url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://security-tracker.debian.org/tracker/CVE-2023-5752 url
- https://access.redhat.com/security/cve/cve-2023-5752 url
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-797928fed3 url
- https://www.suse.com/security/cve/CVE-2023-5752.html url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2025-0923SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2025-1020SE47 url
- https://github.com/pypa/pip/pull/12306/commits/389cb799d0da9a840749fcd14878928467ed49b4 advisory