Junglewise Threat Intelligence

CVE-2013-1629: PYSEC-2013-8 - pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which all

CVE-2013-1629 · Severity: low · CVSS 3.1 · Published 2013-08-06

Technologies: pip (PyPI). Vendors: PyPI.

Executive brief

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.

Affected products

  • PyPI pip

Related threats