Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-5752
Description:When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.
Test IDs: 1.3.6.1.4.1.25623.1.1.4.2023.4987.1   1.3.6.1.4.1.25623.1.0.856452   1.3.6.1.4.1.25623.1.0.886571   1.3.6.1.4.1.25623.1.1.4.2024.0892.1   1.3.6.1.4.1.25623.1.0.886510   1.3.6.1.4.1.25623.1.0.886813   1.3.6.1.4.1.25623.1.0.886613   1.3.6.1.4.1.25623.1.1.10.2025.0055   1.3.6.1.4.1.25623.1.0.886466   1.3.6.1.4.1.25623.1.0.833867  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-5752
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KFC2SPFG5FLCZBYY2K3T5MFW2D22NG6E/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/622OZXWG72ISQPLM5Y57YCVIMWHD4C3U/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/65UKKF5LBHEFDCUSPBHUN4IHYX7SRMHH/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YBSB3SUPQ3VIFYUMHPO3MEQI4BJAXKCZ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FXUVMJM25PUAZRQZBF54OFVKTY3MINPW/
https://github.com/pypa/pip/pull/12306
https://github.com/pypa/pip/pull/12306
https://mail.python.org/archives/list/security-announce@python.org/thread/F4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL/
https://mail.python.org/archives/list/security-announce@python.org/thread/F4PL35U6X4VVHZ5ILJU3PWUWN7H7LZXL/




© 1998-2025 E-Soft Inc. All rights reserved.