Package | Installed | Affected | Info |
---|---|---|---|
pip | 22.3.1 | <23.3 |
show Affected versions of Pip are vulnerable to Command Injection. When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. |
pip | 22.3.1 | <25.0 |
show Pip solves a security vulnerability that previously allowed maliciously crafted wheel files to execute unauthorized code during installation. |
Package | Installed | Affected | Info |
---|---|---|---|
pip | 22.3.1 | <23.3 |
show Affected versions of Pip are vulnerable to Command Injection. When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. |
pip | 22.3.1 | <25.0 |
show Pip solves a security vulnerability that previously allowed maliciously crafted wheel files to execute unauthorized code during installation. |
Package | Installed | Affected | Info |
---|---|---|---|
pip | 22.3.1 | <23.3 |
show Affected versions of Pip are vulnerable to Command Injection. When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. |
pip | 22.3.1 | <25.0 |
show Pip solves a security vulnerability that previously allowed maliciously crafted wheel files to execute unauthorized code during installation. |
Package | Installed | Affected | Info |
---|---|---|---|
pip | 22.3.1 | <23.3 |
show Affected versions of Pip are vulnerable to Command Injection. When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. |
pip | 22.3.1 | <25.0 |
show Pip solves a security vulnerability that previously allowed maliciously crafted wheel files to execute unauthorized code during installation. |
Package | Installed | Affected | Info |
---|---|---|---|
pip | 22.3.1 | <23.3 |
show Affected versions of Pip are vulnerable to Command Injection. When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. |
pip | 22.3.1 | <25.0 |
show Pip solves a security vulnerability that previously allowed maliciously crafted wheel files to execute unauthorized code during installation. |
Package | Installed | Affected | Info |
---|---|---|---|
pip | 22.3.1 | <23.3 |
show Affected versions of Pip are vulnerable to Command Injection. When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. |
pip | 22.3.1 | <25.0 |
show Pip solves a security vulnerability that previously allowed maliciously crafted wheel files to execute unauthorized code during installation. |
Package | Installed | Affected | Info |
---|---|---|---|
pip | 22.3.1 | <23.3 |
show Affected versions of Pip are vulnerable to Command Injection. When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. |
pip | 22.3.1 | <25.0 |
show Pip solves a security vulnerability that previously allowed maliciously crafted wheel files to execute unauthorized code during installation. |
Package | Installed | Affected | Info |
---|---|---|---|
pip | 22.3.1 | <23.3 |
show Affected versions of Pip are vulnerable to Command Injection. When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. |
pip | 22.3.1 | <25.0 |
show Pip solves a security vulnerability that previously allowed maliciously crafted wheel files to execute unauthorized code during installation. |
Package | Installed | Affected | Info |
---|---|---|---|
pip | 22.3.1 | <23.3 |
show Affected versions of Pip are vulnerable to Command Injection. When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. |
pip | 22.3.1 | <25.0 |
show Pip solves a security vulnerability that previously allowed maliciously crafted wheel files to execute unauthorized code during installation. |
https://pyup.io/repos/github/JeffValenti/SME/python-3-shield.svg
[](https://pyup.io/repos/github/JeffValenti/SME/)
.. image:: https://pyup.io/repos/github/JeffValenti/SME/python-3-shield.svg :target: https://pyup.io/repos/github/JeffValenti/SME/ :alt: Python 3
<a href="https://pyup.io/repos/github/JeffValenti/SME/"><img src="https://pyup.io/repos/github/JeffValenti/SME/shield.svg" alt="Python 3" /></a>
!https://pyup.io/repos/github/JeffValenti/SME/python-3-shield.svg(Python 3)!:https://pyup.io/repos/github/JeffValenti/SME/
{<img src="https://pyup.io/repos/github/JeffValenti/SME/python-3-shield.svg" alt="Python 3" />}[https://pyup.io/repos/github/JeffValenti/SME/]
https://pyup.io/repos/github/JeffValenti/SME/shield.svg
[](https://pyup.io/repos/github/JeffValenti/SME/)
.. image:: https://pyup.io/repos/github/JeffValenti/SME/shield.svg :target: https://pyup.io/repos/github/JeffValenti/SME/ :alt: Updates
<a href="https://pyup.io/repos/github/JeffValenti/SME/"><img src="https://pyup.io/repos/github/JeffValenti/SME/shield.svg" alt="Updates" /></a>
!https://pyup.io/repos/github/JeffValenti/SME/shield.svg(Updates)!:https://pyup.io/repos/github/JeffValenti/SME/
{<img src="https://pyup.io/repos/github/JeffValenti/SME/shield.svg" alt="Updates" />}[https://pyup.io/repos/github/JeffValenti/SME/]