Vulnerability Details CVE-2023-5752
When installing a package from a Mercurial VCS URL (ie "pip install
hg+...") with pip prior to v23.3, the specified Mercurial revision could
be used to inject arbitrary configuration options to the "hg clone"
call (ie "--config"). Controlling the Mercurial configuration can modify
how and which repository is installed. This vulnerability does not
affect users who aren't installing from Mercurial.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.7%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2023-5752
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:pypa:pip:10.0.0
-
cpe:2.3:a:pypa:pip:10.0.1
-
-
-
-
cpe:2.3:a:pypa:pip:19.0.1
-
cpe:2.3:a:pypa:pip:19.0.2
-
cpe:2.3:a:pypa:pip:19.0.3
-
-
cpe:2.3:a:pypa:pip:19.1.1
-
-
cpe:2.3:a:pypa:pip:19.2.1
-
cpe:2.3:a:pypa:pip:19.2.2
-
cpe:2.3:a:pypa:pip:19.2.3
-
-
cpe:2.3:a:pypa:pip:19.3.1
-
-
cpe:2.3:a:pypa:pip:20.0.1
-
cpe:2.3:a:pypa:pip:20.0.2
-
-
cpe:2.3:a:pypa:pip:20.1.1
-
-
cpe:2.3:a:pypa:pip:20.2.1
-
cpe:2.3:a:pypa:pip:20.2.2
-
cpe:2.3:a:pypa:pip:20.2.3
-
cpe:2.3:a:pypa:pip:20.2.4
-
-
cpe:2.3:a:pypa:pip:20.3.1
-
cpe:2.3:a:pypa:pip:20.3.2
-
cpe:2.3:a:pypa:pip:20.3.3
-
cpe:2.3:a:pypa:pip:20.3.4
-
-
cpe:2.3:a:pypa:pip:21.0.1
-
-
cpe:2.3:a:pypa:pip:22.1.1
-
cpe:2.3:a:pypa:pip:22.1.2
-
-
cpe:2.3:a:pypa:pip:22.2.1
-
cpe:2.3:a:pypa:pip:22.2.2
-
-
cpe:2.3:a:pypa:pip:22.3.1
-
-
cpe:2.3:a:pypa:pip:23.0.1
-
-
cpe:2.3:a:pypa:pip:23.1.1
-
cpe:2.3:a:pypa:pip:23.1.2
-
-
cpe:2.3:a:pypa:pip:23.2.1
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-