CVE-2013-1629

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
06/08/2013
Last modified:
15/03/2021

Description

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:* 1.3 (excluding)