vulnerability

Alma Linux: CVE-2019-20916: Moderate: python27:2.7 security update (ALSA-2020-4654)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Sep 4, 2020
Added
May 4, 2022
Modified
Nov 14, 2024

Description

The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.

Solution(s)

alma-upgrade-python-psycopg2-docalma-upgrade-python-sqlalchemy-docalma-upgrade-python2-attrsalma-upgrade-python2-chardetalma-upgrade-python2-coveragealma-upgrade-python2-cythonalma-upgrade-python2-dnsalma-upgrade-python2-docsalma-upgrade-python2-docs-infoalma-upgrade-python2-docutilsalma-upgrade-python2-funcsigsalma-upgrade-python2-idnaalma-upgrade-python2-ipaddressalma-upgrade-python2-markupsafealma-upgrade-python2-mockalma-upgrade-python2-pluggyalma-upgrade-python2-psycopg2alma-upgrade-python2-psycopg2-debugalma-upgrade-python2-psycopg2-testsalma-upgrade-python2-pyalma-upgrade-python2-pymysqlalma-upgrade-python2-pysocksalma-upgrade-python2-pytestalma-upgrade-python2-pytest-mockalma-upgrade-python2-pytzalma-upgrade-python2-pyyamlalma-upgrade-python2-requestsalma-upgrade-python2-rpm-macrosalma-upgrade-python2-setuptools_scmalma-upgrade-python2-sqlalchemy
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.