ALAS-2023-2349

Related Vulnerabilities: CVE-2023-5752  

When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial. (CVE-2023-5752)

ALAS-2023-2349


Amazon Linux 2 Security Advisory: ALAS-2023-2349
Advisory Release Date: 2023-11-29 22:19 Pacific
Advisory Updated Date: 2023-12-04 21:44 Pacific
Severity: Medium

Issue Overview:

When installing a package from a Mercurial VCS URL (ie "pip install
hg+...") with pip prior to v23.3, the specified Mercurial revision could
be used to inject arbitrary configuration options to the "hg clone"
call (ie "--config"). Controlling the Mercurial configuration can modify
how and which repository is installed. This vulnerability does not
affect users who aren't installing from Mercurial. (CVE-2023-5752)


Affected Packages:

python-pip


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update python-pip to update your system.

New Packages:
noarch:
    python2-pip-20.2.2-1.amzn2.0.5.noarch
    python3-pip-20.2.2-1.amzn2.0.5.noarch
    python-pip-wheel-20.2.2-1.amzn2.0.5.noarch

src:
    python-pip-20.2.2-1.amzn2.0.5.src