VDB
GCVE-VVD-MAGEIA-2021-54
GCVE-VVD-MAGEIA-2021-54
Advisory Published
It was discovered that pip did not properly sanitize the filename during pip
install. A remote attacker could possible use this issue to read and write
arbitrary files on the host filesystem as root, resulting in a directory
traversal attack (CVE-2019-20916).
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP
request method, as demonstrated by inserting CR and LF control characters in
the first argument of putrequest(). The python-pip package bundles a copy of
python-urllib3, which was affected by this issue. The bundled copy was
patched to fix the issue (CVE-2020-26137).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | python-pip | 0 (affected), 19.0.3-1.3.mga7 (unaffected), 0 (affected), 19.0.3-1.3.mga7 (unaffected) | — |
| Mageia | trackballs | 0 (affected), 1.3.2-1.mga8 (unaffected) | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.