VDB

GCVE-VVD-MAGEIA-2021-54

GCVE-VVD-MAGEIA-2021-54
Advisory Published
Vulnetix · Advisory published March 30, 2021
It was discovered that pip did not properly sanitize the filename during pip install. A remote attacker could possible use this issue to read and write arbitrary files on the host filesystem as root, resulting in a directory traversal attack (CVE-2019-20916). urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). The python-pip package bundles a copy of python-urllib3, which was affected by this issue. The bundled copy was patched to fix the issue (CVE-2020-26137).

Affected Products

VendorProductVersionsPlatforms
Mageiapython-pip0 (affected), 19.0.3-1.3.mga7 (unaffected), 0 (affected), 19.0.3-1.3.mga7 (unaffected)
Mageiatrackballs0 (affected), 1.3.2-1.mga8 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›