漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
pip can extract console_scripts and gui_scripts outside installation directory
Vulnerability Description
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
pip 安全漏洞
Vulnerability Description
pip是Python Packaging Authority开源的一个Python包安装程序。 pip存在安全漏洞,该漏洞源于安装恶意Python wheel时,特制入口点名称使用目录遍历或绝对路径,可能导致任意文件覆盖。
CVSS Information
N/A
Vulnerability Type
N/A