ALAS-2023-442


Amazon Linux 2023 Security Advisory: ALAS-2023-442
Advisory Release Date: 2023-12-06 07:45 Pacific
Advisory Updated Date: 2023-12-14 21:43 Pacific
Severity: Medium

Issue Overview:

When installing a package from a Mercurial VCS URL (ie "pip install
hg+...") with pip prior to v23.3, the specified Mercurial revision could
be used to inject arbitrary configuration options to the "hg clone"
call (ie "--config"). Controlling the Mercurial configuration can modify
how and which repository is installed. This vulnerability does not
affect users who aren't installing from Mercurial. (CVE-2023-5752)


Affected Packages:

python-pip


Issue Correction:
Run dnf update python-pip --releasever 2023.3.20231211 to update your system.

New Packages:
noarch:
    python3-pip-wheel-21.3.1-2.amzn2023.0.7.noarch
    python3-pip-21.3.1-2.amzn2023.0.7.noarch

src:
    python-pip-21.3.1-2.amzn2023.0.7.src