Command Injection in pip - CVE-2023-5752
Published: December 28, 2023
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation when installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip. A remote attacker who controls the repository can use the specified Mercurial revision to inject arbitrary configuration options to the "hg clone" call (ie "--config").
Affected software
PowerStore 3000X
PowerStore 5000X
PowerStore 9000X
PowerStore 7000X
PowerStore 1000X
PowerStoreX OS
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
Python 3 Module
openSUSE Leap
openEuler
Anolis OS
Fedora
Guardium Data Security Center (GDSC)
watsonx.ai on Cloud Pak for Data
Business Automation Insights
ObjectScale
Netezza Performance Server Replication Services
QRadar Deployment Intelligence App
PowerStore T
Security QRadar EDR
DataStage on Cloud Pak for Data
Maximo Application Suite - IoT Component
Robotic Process Automation for Cloud Pak
PeopleSoft Enterprise PeopleTools
Splunk Enterprise
python3x-sqlparse (Red Hat package)
python-sqlparse (Red Hat package)
python3x-pulp-ansible (Red Hat package)
python-pulp-ansible (Red Hat package)
automation-eda-controller (Red Hat package)
ansible-rulebook (Red Hat package)
receptor (Red Hat package)
python3x-pydantic (Red Hat package)
python-pydantic (Red Hat package)
ansible-automation-platform-installer (Red Hat package)
ansible-core (Red Hat package)
python3x-requests (Red Hat package)
python-requests (Red Hat package)
python3x-jinja2 (Red Hat package)
python-jinja2 (Red Hat package)
python3x-idna (Red Hat package)
python-idna (Red Hat package)
python3x-aiohttp (Red Hat package)
python-aiohttp (Red Hat package)
python3x-pulpcore (Red Hat package)
python-pulpcore (Red Hat package)
automation-controller (Red Hat package)
automation-hub (Red Hat package)
python3x-galaxy-ng (Red Hat package)
python-galaxy-ng (Red Hat package)
python3x-social-auth-app-django (Red Hat package)
python-social-auth-app-django (Red Hat package)
pypy
python-pip
python3-pip
python3x-pillow (Red Hat package)
python-pillow (Red Hat package)
python-pip-help
python-pip-wheel
python2-pip
python3x-gunicorn (Red Hat package)
python-gunicorn (Red Hat package)
python311-pip
python3x-black (Red Hat package)
python-black (Red Hat package)
python312-pip
dev-python/pip
python3x-pyOpenSSL (Red Hat package)
python-pyOpenSSL (Red Hat package)
python3x-cryptography (Red Hat package)
python-cryptography (Red Hat package)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Cloud Pak for Business Automation
IBM Robotic Process Automation
IBM Qradar SIEM
IBM Netezza Analytics
How to mitigate CVE-2023-5752
Guardium Data Security Center (GDSC) - addressed in versions 3.6.1, 3.8.5
watsonx.ai on Cloud Pak for Data - update to 5.3.1
Splunk Enterprise - addressed in versions 9.0.9, 9.1.4, 9.2.1
Business Automation Insights - update to 25.0.0.0.1
python3x-sqlparse (Red Hat package) - update to 0.5.0-1.el8ap
python-sqlparse (Red Hat package) - update to 0.5.0-1.el9ap
python3x-pulp-ansible (Red Hat package) - update to 0.20.7-1.el8ap
python-pulp-ansible (Red Hat package) - update to 0.20.7-1.el9ap
automation-eda-controller (Red Hat package) - addressed in versions 1.0.7-1.el8ap, 1.0.7-1.el9ap
ansible-rulebook (Red Hat package) - addressed in versions 1.0.7-1.el8ap, 1.0.7-1.el9ap
ObjectScale - update to 1.4.0
receptor (Red Hat package) - addressed in versions 1.4.8-1.el8ap, 1.4.8-1.el9ap
python3x-pydantic (Red Hat package) - update to 1.10.15-1.el8ap
python-pydantic (Red Hat package) - update to 1.10.15-1.el9ap
ansible-automation-platform-installer (Red Hat package) - addressed in versions 2.4-7.1.el8ap, 2.4-7.1.el9ap
ansible-core (Red Hat package) - addressed in versions 2.15.11-1.el8ap, 2.15.11-1.el9ap
python3x-requests (Red Hat package) - update to 2.32.2-1.el8ap
python-requests (Red Hat package) - update to 2.32.2-1.el9ap
Netezza Performance Server Replication Services - update to 3.0.5.1
QRadar Deployment Intelligence App - update to 3.0.16
python3x-jinja2 (Red Hat package) - update to 3.1.4-1.el8ap
python-jinja2 (Red Hat package) - update to 3.1.4-1.el9ap
PowerStoreX OS - update to 3.2.1.5-2424458
PowerStore T - update to 3.6.1.4-2413340
python3x-idna (Red Hat package) - update to 3.7-1.el8ap
python-idna (Red Hat package) - update to 3.7-1.el9ap
python3x-aiohttp (Red Hat package) - update to 3.9.5-1.el8ap
python-aiohttp (Red Hat package) - update to 3.9.5-1.el9ap
Security QRadar EDR - update to 3.12.8
python3x-pulpcore (Red Hat package) - update to 3.28.27-1.el8ap
python-pulpcore (Red Hat package) - update to 3.28.27-1.el9ap
automation-controller (Red Hat package) - addressed in versions 4.5.7-1.el8ap, 4.5.7-1.el9ap
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.3
automation-hub (Red Hat package) - addressed in versions 4.9.2-1.el8ap, 4.9.2-1.el9ap
python3x-galaxy-ng (Red Hat package) - update to 4.9.2-1.el8ap
python-galaxy-ng (Red Hat package) - update to 4.9.2-1.el9ap
DataStage on Cloud Pak for Data - update to 5.1.2
python3x-social-auth-app-django (Red Hat package) - update to 5.4.1-1.el8ap
python-social-auth-app-django (Red Hat package) - update to 5.4.1-1.el9ap
pypy - addressed in versions 7.3.15-3.fc38, 7.3.15-3.fc39, 7.3.15-3.fc40, 7.3.15-3.fc41
IBM Qradar SIEM - update to 7.5.0 Update Pack 10 IF01
Maximo Application Suite - IoT Component - addressed in versions 8.7.21, 8.8.17, 9.0.7
python-pip - update to 10.0.1-13.14.1
python3-pip - update to 10.0.1-13.14.1
python3x-pillow (Red Hat package) - update to 10.3.0-1.el8ap
python-pillow (Red Hat package) - update to 10.3.0-1.el9ap
IBM Netezza Analytics - update to 11.2.29
python3-pip - addressed in versions 20.2.2-19, 21.3.1-18
python-pip-help - addressed in versions 20.2.2-19, 21.3.1-18
python-pip-wheel - addressed in versions 20.2.2-19, 21.3.1-18
python-pip - addressed in versions 20.2.2-19, 21.3.1-18
python2-pip - update to 20.2.2-19
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.19, 23.0.19
IBM Robotic Process Automation - addressed in versions 21.0.7.19, 23.0.19
python-pip - update to 21.3.1-2
python3x-gunicorn (Red Hat package) - update to 22.0.0-1.el8ap
python-gunicorn (Red Hat package) - update to 22.0.0-1.el9ap
python-pip - addressed in versions 22.3.1-4.fc38, 23.2.1-2.fc39
python311-pip - update to 22.3.1-150400.17.12.1
python3x-black (Red Hat package) - update to 22.8.0-2.el8ap
python-black (Red Hat package) - update to 22.8.0-2.el9ap
python312-pip - update to 23.2.1-150600.3.3.1
dev-python/pip - update to 23.3
python3-pip - update to 23.3.1-1
python-pip-wheel - update to 23.3.1-1
python3x-pyOpenSSL (Red Hat package) - update to 24.1.0-1.el8ap
python-pyOpenSSL (Red Hat package) - update to 24.1.0-1.el9ap
python3x-cryptography (Red Hat package) - update to 42.0.5-1.el8ap
python-cryptography (Red Hat package) - update to 42.0.5-1.el9ap
External References
Related Security Bulletins
- Command injection in Python pip
- SUSE update for python-pip
- SUSE update for python-pip
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Fedora 38 update for python-pip
- Fedora 39 update for python-pip
- Fedora 41 update for pypy
- Fedora 38 update for pypy
- Fedora 39 update for pypy
- Fedora 40 update for pypy
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Splunk Enterprise update for third-party components
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in IBM Security QRadar EDR
- SUSE update for python312-pip
- Multiple vulnerabilities in PeopleSoft Enterprise PeopleTools
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Robotic Process Automation
- Multiple vulnerabilities in Dell PowerStore T
- Gentoo update for pip
- Multiple vulnerabilities in Guardium Data Security Center
- Multiple vulnerabilities in IBM QRadar Deployment Intelligence App
- Amazon Linux AMI update for python-pip
- IBM DataStage on Cloud Pak for Data update for Pip
- Anolis OS update for python-pip
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Multiple vulnerabilities in Dell PowerStore X
- Multiple vulnerabilities in IBM Netezza Analytics - NPS
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in IBM Guardium Data Security Center
- Multiple vulnerabilities in IBM Netezza Performance Server Replication Services
- openEuler 22.03 LTS SP4 update for python-pip
- openEuler 20.03 LTS SP4 update for python-pip
- IBM watsonx.ai on Cloud Pak for Data update for pip package