Related Vulnerabilities: CVE-2023-5752  

DescriptionA flaw was found in the Python pip package. The pip could allow a local authenticated attacker to bypass security restrictions, due to a flaw when installing a package from a Mercurial VCS URL. By sending a specially crafted request, an attacker could exploit this vulnerability to inject arbitrary configuration options to the "hg clone" call to modify how and which repository is installed.A flaw was found in the Python pip package. The pip could allow a local authenticated attacker to bypass security restrictions, due to a flaw when installing a package from a Mercurial VCS URL. By sending a specially crafted request, an attacker could exploit this vulnerability to inject arbitrary configuration options to the "hg clone" call to modify how and which repository is installed.

Affected Packages and Issued Red Hat Security Errata

Unless explicitly stated as not affected, all previous versions of packages in any minor update stream of a product listed here should be assumed vulnerable, although may not have been subject to full analysis.