{"id":"GHSA-27x4-j476-jp5f","summary":"Setuptools vulnerable to Man-in-the-middle attacks","details":"easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.","aliases":["CVE-2013-1633","PYSEC-2013-22"],"modified":"2024-10-22T16:46:12.907816Z","published":"2022-05-17T05:01:02Z","database_specific":{"nvd_published_at":"2013-08-06T02:52:00Z","cwe_ids":["CWE-319"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-08-29T18:46:57Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1633"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/setuptools/PYSEC-2013-22.yaml"},{"type":"PACKAGE","url":"https://github.com/pypa/setuptools"},{"type":"WEB","url":"https://pypi.python.org/pypi/setuptools/0.9.8#changes"},{"type":"WEB","url":"http://www.reddit.com/r/Python/comments/17rfh7/warning_dont_use_pip_in_an_untrusted_network_a"}],"affected":[{"package":{"name":"setuptools","ecosystem":"PyPI","purl":"pkg:pypi/setuptools"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7"}]}],"versions":["0.6b1","0.6b2","0.6b3","0.6b4","0.6c1","0.6c10","0.6c11","0.6c2","0.6c3","0.6c4","0.6c5","0.6c6","0.6c7","0.6c8","0.6c9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-27x4-j476-jp5f/GHSA-27x4-j476-jp5f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}