CVE-2013-1629Improper Input Validation in PIP

Severity
6.8MEDIUMNVD
EPSS
39.9%
top 2.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 6
Latest updateMay 13

Description

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

NVDpypa/pip< 1.3
PyPIpypa/pip< 1.3

Patches

🔴Vulnerability Details

4
GHSA
Improper Input Validation in pip2022-05-13
OSV
Improper Input Validation in pip2022-05-13
OSV
CVE-2013-1629: pip before 12013-08-06
CVEList
CVE-2013-1629: pip before 12013-08-06

📋Vendor Advisories

1
Debian
CVE-2013-1629: python-pip - pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does...2013

💬Community

3
Bugzilla
CVE-2013-1629 python-pip: insecure installation mechanism [fedora-all]2013-05-28
Bugzilla
CVE-2013-1629 python-pip: insecure installation mechanism [epel-all]2013-05-28
Bugzilla
CVE-2013-1629 python-pip: insecure installation mechanism2013-05-28
CVE-2013-1629 — Improper Input Validation in Pypa PIP | cvebase