On Mon Sep 7, 2026 at 10:22 AM CEST, Hetvi Thakar -X (hthakar - E INFOCHIPS 
PRIVATE LIMITED at Cisco) via lists.openembedded.org wrote:
> From: Hetvi Thakar <[email protected]>
>
> Analysis:
> - NVD marks CVE-2018-20225 as disputed. [1]
> - pip searches all configured package indexes without priority and selects
>   the highest matching version. --extra-index-url adds an equal-priority
>   package source. [2]
> - Exploitation requires use of --extra-index-url and an attacker-published,
>   higher-version package with the name of a private package. [1]
> - Upstream closed the related report as not planned, and Red Hat classified
>   the issue as WONTFIX because this behavior is intentional. [3][4]
> - Record the disputed status; no source patch is available.
>
> Reference:
> [1] https://nvd.nist.gov/vuln/detail/CVE-2018-20225
> [2] https://pip.pypa.io/en/stable/cli/pip_install/
> [3] https://github.com/pypa/pip/issues/12874
> [4] https://bugzilla.redhat.com/show_bug.cgi?id=1835736
>
> Signed-off-by: Hetvi Thakar <[email protected]>
> ---
>  meta/recipes-devtools/python/python3-pip_26.0.1.bb | 2 ++
>  1 file changed, 2 insertions(+)
>
> diff --git a/meta/recipes-devtools/python/python3-pip_26.0.1.bb 
> b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
> index 1a2cbc397a..46fa63e6a6 100644
> --- a/meta/recipes-devtools/python/python3-pip_26.0.1.bb
> +++ b/meta/recipes-devtools/python/python3-pip_26.0.1.bb
> @@ -34,6 +34,8 @@ SRC_URI[sha256sum] = 
> "c4037d8a277c89b320abe636d59f91e6d0922d08a05b60e85e53b29661
>  
>  CVE_PRODUCT = "pypa:pip"
>  
> +CVE_STATUS[CVE-2018-20225] = "disputed: Exploitation requires use of 
> --extra-index-url with a private package not present on the primary public 
> index; pip intentionally selects the highest version across configured 
> indexes"
> +
>  do_install:append(){
>       # pip vendors distlib which ships Windows launcher templates (*.exe).
>       # Keep them only when building for a Windows (mingw) host.

Hello,

We have decided to upgrade sbom-cve-check on wrynose. This upgrade
include the feature of globally ignoring all disputed CVEs.

I've taken the upgrade in my current series so this patch becomes
redundant and I've dropped it, sorry.

Thanks!
-- 
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#246077): 
https://lists.openembedded.org/g/openembedded-core/message/246077
Mute This Topic: https://lists.openembedded.org/mt/121125677/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

  • ... Hetvi Thakar -X (hthakar - E INFOCHIPS PRIVATE LIMITED at Cisco) via lists.openembedded.org
    • ... Yoann Congal via lists.openembedded.org

Reply via email to