CVE Feed

    Dashboard / CVE / CVE-2021-3572

    CVE-2021-3572

    A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

    Published:Apr 24, 2021
    Last Modified:Aug 25, 2026
    EPS:Nov 10, 2021
    EPSS Score:0.01687
    CVSS Score:5.7

    Affected Products

    Vendor
    Oracle
    Product
    Agile Product Lifecycle Management
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Network Function Cloud Native Environment
    Vendor
    Oracle
    Product
    Communications Cloud Native Core Policy
    Vendor
    Pypa
    Product
    Pip
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Rhel Software Collections

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High