FlawAtlas
Search the atlas
CVE-2013-5123 Moderate

CVE-2013-5123

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

Exploit probability 8.0%
Published November 5, 2019
Required by Not available
Last source change April 16, 2026

02 / AFFECTED SOFTWARE

Affected packages

PyPI pip

28 explicit affected versions

PyPI pip

28 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2013-5123

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

View original source
Open Source Vulnerabilities GHSA-c5h8-cq4v-cvfm

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

View original source
Open Source Vulnerabilities PYSEC-2019-160

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

View original source

05 / REFERENCES

Further evidence