CVE-2021-3572
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.8%
exploitation probability
1.8%top 22% of all CVEs
observed exploitation
nono source reports it
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
Affected products
n/a · python-pip