Executive brief
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
Affected products
- PyPI pip
Junglewise Threat Intelligence
CVE-2013-5123 · Severity: low · CVSS 3.1 · Published 2019-11-05
Technologies: pip (PyPI). Vendors: PyPI.
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.