Known vulnerabilities in python-pip (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:python-pip_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 7
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting python-pip (Red Hat package) python-pip (Red Hat package) is affected by 7 known vulnerabilities: 2 high, 5 medium Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU67583 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2007-4559
CWE-22 High
Available
No
9.0.3-22.1.el8_6, 9.0.3-23.el8, 21.2.3-7.el9 22.09.2022 SB2007082801
SB2022120206
SB2023060825
and 68 more
#VU62512 - Improper input validation
CVE-2021-3572
CWE-20 Medium
No
No
9.0.3-20.el8 22.04.2022 SB2022042257
SB2022042259
SB2021071390
and 51 more
#VU48600 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-20916
CWE-22 Medium
No
No
9.0.3-18.el8 04.09.2020 SB2020090420
SB2020112328
SB2020122208
and 29 more
#VU26413 - Exposure of sensitive information to an unauthorized actor
CVE-2018-20060
CWE-200 Medium
Available
No
9.0.3-7.el7_7, 9.0.3-7.el7_8, 9.0.3-16.el8 26.03.2020 SB2020032626
SB2020031827
SB2019091403
and 20 more
#VU26412 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2019-11236
CWE-93 Medium
Available
No
9.0.3-7.el7_7, 9.0.3-7.el7_8, 9.0.3-16.el8 26.03.2020 SB2020032626
SB2020031827
SB2019091504
and 36 more
#VU21780 - Improper Certificate Validation
CVE-2019-11324
CWE-295 Medium
Available
No
9.0.3-7.el7_7, 9.0.3-7.el7_8, 9.0.3-16.el8 15.10.2019 SB2019041823
SB2020031827
SB2019091504
and 19 more
#VU19388 - Credentials Management
CVE-2018-18074
CWE-255 High
No
No
9.0.3-7.el7_7, 9.0.3-7.el7_8, 9.0.3-16.el8 26.07.2019 SB2019072007
SB2019080710
SB2020032626
and 18 more