Path traversal in py-pip - CVE-2019-20916
Published: September 4, 2020 / Updated: July 20, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences passed via URL to the install command within the _download_http_url() function in _internal/download.py. A remote attacker can send a specially crafted HTTP request with the Content-Disposition header that contains directory traversal characters in the filename and overwrite the /root/.ssh/authorized_keys file.
Affected software
IBM Cloud Pak for Watson AIOps
Guardium Data Security Center (GDSC)
DataStage on Cloud Pak for Data
Netezza Performance Server Replication Services
QRadar Deployment Intelligence App
Maximo Application Suite - IoT Component
EMC Cloud Tiering Appliance
Robotic Process Automation for Cloud Pak
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Enterprise Storage
Oracle Linux
Anolis OS
Fedora
Red Hat Enterprise Linux for Power, little endian
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
openSUSE Leap
Ubuntu
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Netcool Operations Insight
IBM Maximo Application Suite - Manage Component
IBM Robotic Process Automation
IBM Observability with Instana
Oracle Access Manager
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC VxRail Appliance
python-pip-epel
python3-pip (Ubuntu package)
python-pip (Ubuntu package)
python-pip (Red Hat package)
python-virtualenv
python-virtualenv (Red Hat package)
python2-pip
python3-pip
python3-pip-wheel
IBM Netezza Analytics
How to mitigate CVE-2019-20916
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0
Quay - update to 3.3.3
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
DataStage on Cloud Pak for Data - update to 5.1.3
Netcool Operations Insight - update to 1.6.11
Netezza Performance Server Replication Services - update to 3.0.5.1
QRadar Deployment Intelligence App - update to 3.0.16
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC VxRail Appliance - update to 7.0.411
python-pip-epel - update to 8.1.2-14.el7
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.17, 8.7.11, 9.0.2
Maximo Application Suite - IoT Component - addressed in versions 8.7.21, 8.8.17, 9.0.7
python3-pip (Ubuntu package) - update to 9.0.1-2.3~ubuntu1.18.04.4
python-pip (Ubuntu package) - update to 9.0.1-2.3~ubuntu1.18.04.4
python-pip (Red Hat package) - update to 9.0.3-18.el8
IBM Netezza Analytics - update to 11.2.29
EMC Cloud Tiering Appliance - update to 13.2.0.2.22
python-virtualenv - update to 15.1.0-7
python-virtualenv (Red Hat package) - update to 15.1.0-7.el7_9
python2-pip - update to 20.0.2-150100.6.18.1
python3-pip - update to 20.0.2-150100.6.18.1
python3-pip-wheel - update to 20.0.2-150100.6.18.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.19, 23.0.19
IBM Robotic Process Automation - addressed in versions 21.0.7.19, 23.0.19
IBM Observability with Instana - update to 277
External References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00005.html
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00010.html
- https://github.com/gzpan123/pip/commit/a4c735b14a62f9cb864533808ac63936704f2ace
- https://github.com/pypa/pip/compare/19.1.1...19.2
- https://github.com/pypa/pip/issues/6413
- https://lists.debian.org/debian-lts-announce/2020/09/msg00010.html
Related Security Bulletins
- Path traversal in Python PIP installation package
- Multiple vulnerabilities in Red Hat Openshift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Storage
- Multiple vulnerabilities in Red Hat Quay
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Dell EMC Unity
- Red Hat Enterprise Linux 7 update for python-virtualenv
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Function Cloud Native Environment
- Multiple vulnerabilities in Oracle Linux
- CentOS 7 update for python-virtualenv
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data update for Python
- Red Hat Enterprise Linux 8 update for python-pip
- SUSE update for python-pip
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- SUSE update for python-pip
- Multiple vulnerabilities in Oracle Access Manager
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Maximo Application Suite - Manage Component
- Multiple vulnerabilities in IBM Robotic Process Automation
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in IBM QRadar Deployment Intelligence App
- Anolis OS update for python-virtualenv
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Ubuntu update for python-pip
- Red Hat Enterprise Linux 8 update for the python27:2.7 module
- Fedora EPEL 7 update for python-pip-epel
- IBM DataStage on Cloud Pak for Data update for pip package
- Multiple vulnerabilities in IBM Netezza Analytics - NPS
- Multiple vulnerabilities in IBM Netezza Performance Server Replication Services