Back

HIGH

python-pip: when --extra-index-url option is used and package does not already exist in the public index, the installation of malicious package with arbitrary version number is possible.

Published May 8, 2020

Description

An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely

Affected products

Remediation

Red Hat statement

Although this issue affects versions of pip shipped with Red Hat Enterprise Linux, Red Hat Software Collections, and Red Hat CodeReady Workspaces, according to the pip documentation, this behavior is intentional when using the --extra-index-url flag, as pip installs the version with the highest version number. As such, Red Hat Product Security has classified this as a low-severity issue, given that it is the intended functionality of pip and requires specific conditions for potential exploitation.

Red Hat mitigation

To protect from any unintended behavior, use --index-url and do not use --extra-index-url OR explicitly set --index-url and use --extra-index-url.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 8, 2020
Updated Apr 15, 2026
Reserved Dec 19, 2018
CISA Vulnrichment
Updated Apr 15, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 28, 2020