EIQ-2020-0015
    
| 
     ID  | 
                
     EIQ-2020-0015  | 
        
| 
     CVE  | 
                |
| 
     Description  | 
                
     pip can enable directory traversal  | 
        
| 
     Date  | 
                
     02 Dec 2020  | 
        
| 
     Severity  | 
                
     3 - HIGH  | 
        
| 
     CVSSv3 score  | 
                
     7.5  | 
        
| 
     Status  | 
                
     Planned for 2.10.0  | 
        
| 
     Assessment  | 
                
     pip versions 19.1.1 and earlier can enable directory traversal. In the _internal/download.py file, the _download_http_url function allows the filename directive of the Content-Disposition response header to hold a URL path pointing to a file as a value. By exploiting this vulnerability, potential attackers can break out of the web server's root directory, and they can access files in other directories. To exploit the vulnerability, a potential attacker would need to carry out a privilege escalation attack to obtain the following access rights: 
  | 
        
| 
     Mitigation  | 
                
     To mitigate this vulnerability: 
 The vulnerability does not affect EclecticIQ Platform: 
 Therefore, there is no exposure surface to exploit the vulnerability in the platform.  | 
        
| 
     Affected versions  | 
                
     2.8.0 and earlier.  | 
        
| 
     Notes  | 
                
     For more information, see: 
 See also:  | 
        
< Back to all security issues and mitigation actions
In release notes 2.9.0