Back

HIGH

python-pip: directory traversal in _download_http_url() function in src/pip/_internal/download.py

Published Sep 4, 2020

Description

The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.

Affected products

Remediation

Red Hat statement

This issue has been rated as having Moderate impact because of the preconditions needed to trigger the flaw: it only affects Python Wheels and requires the user to pip-install a wheel from a malicious server. Installing software from untrusted servers is insecure by definition and strongly discouraged, as it may lead to system compromise regardless of this CVE. This flaw did not affect the versions of `python-pip` in Python 3.8 as shipped with Red Hat Enterprise Linux 8 and Red Hat Software Collections 3, as they already included the fix for this CVE.

Red Hat mitigation

Avoid downloading or installing packages from potentially malicious servers via the command-line "pip download" or "pip install".

Weaknesses (1)

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 4, 2020
Updated Aug 5, 2024
Reserved Sep 4, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 16, 2019
GHSA-GPVV-69J7-GWJ8