{"id":"CVE-2013-1630","aliases":["PYSEC-2013-10"],"url":"https://o3.security/vulnerability/CVE-2013-1630","summary":"pyshop vulnerable to man-in-the-middle attacks due to using HTTP to retrieve packages from the PyPI repository","details":"pyshop before 0.7.1 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a download operation.","published":"2022-05-17T05:03:06Z","modified":"2024-10-14T18:36:24.594642Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pyshop","fixedVersion":"0.7.1"}],"fix":{"url":"https://github.com/mardiros/pyshop/commit/ffadb0bcdef1e385884571670210cfd6ba351784","label":"mardiros/pyshop@ffadb0b"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1630"},{"type":"WEB","url":"https://github.com/mardiros/pyshop/commit/ffadb0bcdef1e385884571670210cfd6ba351784"},{"type":"PACKAGE","url":"https://github.com/mardiros/pyshop"},{"type":"WEB","url":"https://github.com/mardiros/pyshop/blob/master/CHANGES.txt"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pyshop/PYSEC-2013-10.yaml"},{"type":"WEB","url":"http://www.reddit.com/r/Python/comments/17rfh7/warning_dont_use_pip_in_an_untrusted_network_a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-10-14T18:36:24.594642Z"}}