Junglewise Threat Intelligence

CVE-2013-5123: PYSEC-2019-160 - The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers

CVE-2013-5123 · Severity: low · CVSS 3.1 · Published 2019-11-05

Technologies: pip (PyPI). Vendors: PyPI.

Executive brief

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

Affected products

  • PyPI pip

Related threats