Sploitus

CVE-2013-1629

No indexed exploits for CVE-2013-1629 yet

pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation.

Affected products
Pip
Pypa Pip
< 1.3
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
6.2% (93th percentile)
Weakness
CWE-20
NVD status
Modified
Published
2013-08-06
CVE-2013-1629 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2013-1629 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2013-1629 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.