Your submission was sent successfully! Close

CVE-2019-20916

Published: 4 September 2020

The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
python-pip
Launchpad, Ubuntu, Debian
bionic
Released (9.0.1-2.3~ubuntu1.18.04.4)
focal Not vulnerable
(20.0.2-5ubuntu1)
groovy Not vulnerable

hirsute Not vulnerable

impish Not vulnerable

jammy Not vulnerable

precise Does not exist

trusty Needs triage

upstream
Released (20.0.2-1)
xenial Ignored
(end of standard support, was needs-triage)