python-pip: directory traversal in _download_http_url() function in src/pip/_internal/download.py
Published Sep 4, 2020
8.7
HIGHCVSS 4.0
EPSS 3.00%
Description
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.
Affected products
No data.
Configuration 3
- 9.0
Configuration 4
- 1.10.0
- 22.1.0
- 1.15.0
No data.
Red Hat Enterprise Linux 7
python-virtualenv-0:15.1.0-7.el7_9
Fixed · RHSA-2022:5234
Red Hat Enterprise Linux 8
python-pip-0:9.0.3-18.el8
Fixed · RHSA-2020:4432
Red Hat Enterprise Linux 8
python-pip-0:9.0.3-18.el8
Fixed · RHSA-2020:4432
Red Hat Enterprise Linux 8
python27:2.7-8030020200819165638.851f4228
Fixed · RHSA-2020:4654
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-python36-python-0:3.6.12-1.el6
Fixed · RHSA-2020:4285
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-python36-python-pip-0:9.0.1-5.el6
Fixed · RHSA-2020:4285
Red Hat Software Collections for Red Hat Enterprise Linux 6
rh-python36-python-virtualenv-0:15.1.0-3.el6
Fixed · RHSA-2020:4285
Red Hat Software Collections for Red Hat Enterprise Linux 7
python27-python-0:2.7.18-2.el7
Fixed · RHSA-2020:4273
Red Hat Software Collections for Red Hat Enterprise Linux 7
python27-python-pip-0:8.1.2-6.el7
Fixed · RHSA-2020:4273
Red Hat Software Collections for Red Hat Enterprise Linux 7
python27-python-virtualenv-0:13.1.0-4.el7
Fixed · RHSA-2020:4273
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python36-python-0:3.6.12-1.el7
Fixed · RHSA-2020:4285
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python36-python-pip-0:9.0.1-5.el7
Fixed · RHSA-2020:4285
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-python36-python-virtualenv-0:15.1.0-3.el7
Fixed · RHSA-2020:4285
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
python27-python-0:2.7.18-2.el7
Fixed · RHSA-2020:4273
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
python27-python-pip-0:8.1.2-6.el7
Fixed · RHSA-2020:4273
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
python27-python-virtualenv-0:13.1.0-4.el7
Fixed · RHSA-2020:4273
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-python36-python-0:3.6.12-1.el7
Fixed · RHSA-2020:4285
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-python36-python-pip-0:9.0.1-5.el7
Fixed · RHSA-2020:4285
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-python36-python-virtualenv-0:15.1.0-3.el7
Fixed · RHSA-2020:4285
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
python27-python-0:2.7.18-2.el7
Fixed · RHSA-2020:4273
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
python27-python-pip-0:8.1.2-6.el7
Fixed · RHSA-2020:4273
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
python27-python-virtualenv-0:13.1.0-4.el7
Fixed · RHSA-2020:4273
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python36-python-0:3.6.12-1.el7
Fixed · RHSA-2020:4285
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python36-python-pip-0:9.0.1-5.el7
Fixed · RHSA-2020:4285
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-python36-python-virtualenv-0:15.1.0-3.el7
Fixed · RHSA-2020:4285
Red Hat Enterprise Linux 7
python-pip
Will not fix
Red Hat Enterprise Linux 8
python38:3.8/python3x-pip
Not affected
Red Hat Software Collections
rh-python38-python-pip
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | python-virtualenv-0:15.1.0-7.el7_9 | Fixed | RHSA-2022:5234 |
| Red Hat Enterprise Linux 8 | python-pip-0:9.0.3-18.el8 | Fixed | RHSA-2020:4432 |
| Red Hat Enterprise Linux 8 | python-pip-0:9.0.3-18.el8 | Fixed | RHSA-2020:4432 |
| Red Hat Enterprise Linux 8 | python27:2.7-8030020200819165638.851f4228 | Fixed | RHSA-2020:4654 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-python36-python-0:3.6.12-1.el6 | Fixed | RHSA-2020:4285 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-python36-python-pip-0:9.0.1-5.el6 | Fixed | RHSA-2020:4285 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-python36-python-virtualenv-0:15.1.0-3.el6 | Fixed | RHSA-2020:4285 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | python27-python-0:2.7.18-2.el7 | Fixed | RHSA-2020:4273 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | python27-python-pip-0:8.1.2-6.el7 | Fixed | RHSA-2020:4273 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | python27-python-virtualenv-0:13.1.0-4.el7 | Fixed | RHSA-2020:4273 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python36-python-0:3.6.12-1.el7 | Fixed | RHSA-2020:4285 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python36-python-pip-0:9.0.1-5.el7 | Fixed | RHSA-2020:4285 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-python36-python-virtualenv-0:15.1.0-3.el7 | Fixed | RHSA-2020:4285 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | python27-python-0:2.7.18-2.el7 | Fixed | RHSA-2020:4273 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | python27-python-pip-0:8.1.2-6.el7 | Fixed | RHSA-2020:4273 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | python27-python-virtualenv-0:13.1.0-4.el7 | Fixed | RHSA-2020:4273 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-python36-python-0:3.6.12-1.el7 | Fixed | RHSA-2020:4285 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-python36-python-pip-0:9.0.1-5.el7 | Fixed | RHSA-2020:4285 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-python36-python-virtualenv-0:15.1.0-3.el7 | Fixed | RHSA-2020:4285 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | python27-python-0:2.7.18-2.el7 | Fixed | RHSA-2020:4273 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | python27-python-pip-0:8.1.2-6.el7 | Fixed | RHSA-2020:4273 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | python27-python-virtualenv-0:13.1.0-4.el7 | Fixed | RHSA-2020:4273 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python36-python-0:3.6.12-1.el7 | Fixed | RHSA-2020:4285 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python36-python-pip-0:9.0.1-5.el7 | Fixed | RHSA-2020:4285 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-python36-python-virtualenv-0:15.1.0-3.el7 | Fixed | RHSA-2020:4285 |
| Red Hat Enterprise Linux 7 | python-pip | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | python38:3.8/python3x-pip | Not affected | n/a |
| Red Hat Software Collections | rh-python38-python-pip | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue has been rated as having Moderate impact because of the preconditions needed to trigger the flaw: it only affects Python Wheels and requires the user to pip-install a wheel from a malicious server. Installing software from untrusted servers is insecure by definition and strongly discouraged, as it may lead to system compromise regardless of this CVE. This flaw did not affect the versions of `python-pip` in Python 3.8 as shipped with Red Hat Enterprise Linux 8 and Red Hat Software Collections 3, as they already included the fix for this CVE.
Red Hat mitigation
Avoid downloading or installing packages from potentially malicious servers via the command-line "pip download" or "pip install".
References (14)
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00005.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-20916 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1868135 Issue Tracking
- https://github.com/advisories/GHSA-gpvv-69j7-gwj8 Advisory
- https://github.com/gzpan123/pip/commit/a4c735b14a62f9cb864533808ac63936704f2ace x_refsource_MISCPatch
- https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2020-173.yaml
- https://github.com/pypa/pip/compare/19.1.1...19.2 x_refsource_MISCPatch
- https://github.com/pypa/pip/issues/6413 x_refsource_MISCExploitPatch
- https://lists.debian.org/debian-lts-announce/2020/09/msg00010.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-20916
- https://www.cve.org/CVERecord?id=CVE-2019-20916
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.