Path traversal in py-pip - CVE-2019-20916

 

Path traversal in py-pip - CVE-2019-20916

Published: September 4, 2020 / Updated: July 20, 2022


Vulnerability identifier: #VU48600
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-20916
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences passed via URL to the install command within the _download_http_url() function in _internal/download.py. A remote attacker can send a specially crafted HTTP request with the Content-Disposition header that contains directory traversal characters in the filename and overwrite the /root/.ssh/authorized_keys file.


Affected software

py-pip
IBM Cloud Pak for Watson AIOps
Guardium Data Security Center (GDSC)
DataStage on Cloud Pak for Data
Netezza Performance Server Replication Services
QRadar Deployment Intelligence App
Maximo Application Suite - IoT Component
EMC Cloud Tiering Appliance
Robotic Process Automation for Cloud Pak
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Proxy
SUSE Enterprise Storage
Oracle Linux
Anolis OS
Fedora
Red Hat Enterprise Linux for Power, little endian
CentOS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
openSUSE Leap
Ubuntu
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Netcool Operations Insight
IBM Maximo Application Suite - Manage Component
IBM Robotic Process Automation
IBM Observability with Instana
Oracle Access Manager
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC VxRail Appliance
python-pip-epel
python3-pip (Ubuntu package)
python-pip (Ubuntu package)
python-pip (Red Hat package)
python-virtualenv
python-virtualenv (Red Hat package)
python2-pip
python3-pip
python3-pip-wheel
IBM Netezza Analytics

How to mitigate CVE-2019-20916

Install update from vendor's website.

py-pip - update to 19.2
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0
Quay - update to 3.3.3
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
DataStage on Cloud Pak for Data - update to 5.1.3
Netcool Operations Insight - update to 1.6.11
Netezza Performance Server Replication Services - update to 3.0.5.1
QRadar Deployment Intelligence App - update to 3.0.16
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC VxRail Appliance - update to 7.0.411
python-pip-epel - update to 8.1.2-14.el7
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.17, 8.7.11, 9.0.2
Maximo Application Suite - IoT Component - addressed in versions 8.7.21, 8.8.17, 9.0.7
python3-pip (Ubuntu package) - update to 9.0.1-2.3~ubuntu1.18.04.4
python-pip (Ubuntu package) - update to 9.0.1-2.3~ubuntu1.18.04.4
python-pip (Red Hat package) - update to 9.0.3-18.el8
IBM Netezza Analytics - update to 11.2.29
EMC Cloud Tiering Appliance - update to 13.2.0.2.22
python-virtualenv - update to 15.1.0-7
python-virtualenv (Red Hat package) - update to 15.1.0-7.el7_9
python2-pip - update to 20.0.2-150100.6.18.1
python3-pip - update to 20.0.2-150100.6.18.1
python3-pip-wheel - update to 20.0.2-150100.6.18.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.19, 23.0.19
IBM Robotic Process Automation - addressed in versions 21.0.7.19, 23.0.19
IBM Observability with Instana - update to 277

External References

Related Security Bulletins