CVE-2021-3572
published 2021-11-10CVE-2021-3572: A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a…
PriorityP431medium5.7CVSS 3.1
AVNACLPRLUIRSUCNIHAN
EPSS
1.69%
74.5th percentile
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-pip | < python-pip 20.3.4-2 (bookworm) | python-pip 20.3.4-2 (bookworm) |
| msrc | cbl2_python-virtualenv_20.26.6-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_python-pip_19.2-2_on_cbl_mariner_1.0 | — | — |
| oracle | agile_plm | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| paloalto | pan-os | — | — |
| pypa | pip | < 21.1 | 21.1 |
| pypa | pip | >= 0 < 21.1 | 21.1 |
CVSS provenance
nvdv3.15.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_msrc5.7MEDIUM
vendor_oracle5.7MEDIUM
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2018-6594 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2023-38546 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Package Installer for Python) — CVE-2021-3572
vendor_oracle·2022-07-15·CVSS 5.7
CVE-2021-3572 [MEDIUM] Oracle Oracle Communications Risk Matrix: Policy (Package Installer for Python) — CVE-2021-3572
Oracle Oracle Communications Risk Matrix: Policy (Package Installer for Python) vulnerability
CVE: CVE-2021-3572
CVSS: 5.7
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Ubuntu
pip vulnerability
vendor_ubuntu·2022-05-19
CVE-2021-3572 pip vulnerability
Title: pip vulnerability
Summary: pip could be made to install different git revisions.
USN-4961-1 fixed a vulnerability in pip. This update provides the
corresponding updates for Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and
Ubuntu 18.04 ESM.
Original advisory details:
It was discovered that pip incorrectly handled unicode separators in git
references. A remote attacker could possibly use this issue to install a
different revision on a repository.
Instructions: In general, a standard system update will make all the necessary changes.
Oracle
Oracle Oracle Communications Risk Matrix: OC-CNE (python-pip) — CVE-2021-3572
vendor_oracle·2022-04-15·CVSS 5.7
CVE-2021-3572 [MEDIUM] Oracle Oracle Communications Risk Matrix: OC-CNE (python-pip) — CVE-2021-3572
Oracle Oracle Communications Risk Matrix: OC-CNE (python-pip) vulnerability
CVE: CVE-2021-3572
CVSS: 5.7
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Microsoft
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest
vendor_msrc·2021-11-09·CVSS 5.7
CVE-2021-3572 [MEDIUM] CWE-20 A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog
Red Hat
python-pip: Incorrect handling of unicode separators in git references
vendor_redhat·2021-04-24·CVSS 5.7
CVE-2021-3572 [MEDIUM] CWE-20 python-pip: Incorrect handling of unicode separators in git references
python-pip: Incorrect handling of unicode separators in git references
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity.
Statement: This flaw has been rated as having a security impact of Low. To exploit this flaw, the attacker needs access to the repository to create a specially crafted tag and fo
Debian
CVE-2021-3572: python-pip - A flaw was found in python-pip in the way it handled Unicode separators in git r...
vendor_debian·2021·CVSS 5.7
CVE-2021-3572 [MEDIUM] CVE-2021-3572: python-pip - A flaw was found in python-pip in the way it handled Unicode separators in git r...
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
Scope: local
bookworm: resolved (fixed in 20.3.4-2)
bullseye: resolved (fixed in 20.3.4-2)
forky: resolved (fixed in 20.3.4-2)
sid: resolved (fixed in 20.3.4-2)
trixie: resolved (fixed in 20.3.4-2)
GHSA
Improper Input Validation in pip
ghsa·2021-11-15
CVE-2021-3572 [HIGH] CWE-20 Improper Input Validation in pip
Improper Input Validation in pip
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
OSV
Improper Input Validation in pip
osv·2021-11-15
CVE-2021-3572 [HIGH] Improper Input Validation in pip
Improper Input Validation in pip
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
OSV
CVE-2021-3572: A flaw was found in python-pip in the way it handled Unicode separators in git references
osv·2021-11-10·CVSS 5.7
CVE-2021-3572 [MEDIUM] CVE-2021-3572: A flaw was found in python-pip in the way it handled Unicode separators in git references
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1962856https://security.netapp.com/advisory/ntap-20240621-0006/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1962856https://security.netapp.com/advisory/ntap-20240621-0006/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.html
2021-11-10
Published