CVE-2023-5752: When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. Please stabilize 23.3.
cleanup done.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=2bebd1f6ef19542db597ac157cb68c5918ce711d commit 2bebd1f6ef19542db597ac157cb68c5918ce711d Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2025-01-17 07:08:02 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2025-01-17 07:08:10 +0000 [ GLSA 202501-03 ] pip: arbitrary configuration injection Bug: https://bugs.gentoo.org/918427 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202501-03.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+)