Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2023-5752

Description

When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.

POC

Reference

No PoCs from references.

Github

- https://github.com/Anna-Rafaella/Conteneurisation

- https://github.com/CKA-codespace/cg-compare

- https://github.com/CrimsonGabriel/zadanie_1

- https://github.com/Dariani223/DevOpsFinal

- https://github.com/Murken-0/docker-vulnerabilities

- https://github.com/OzNetNerd/CheckovOutputProcessor

- https://github.com/PaulZtx/docker_practice

- https://github.com/RedF0xSec/Weather-Forecasting-App

- https://github.com/Sirelfer/base-project

- https://github.com/Viselabs/zammad-google-cloud-docker

- https://github.com/alex-grandson/docker-python-example

- https://github.com/efrei-ADDA84/20200511

- https://github.com/egorvozhzhov/docker-test

- https://github.com/fetter-io/fetter-py

- https://github.com/fetter-io/fetter-rs

- https://github.com/jbugeja/test-repo

- https://github.com/malinkamedok/devops_sandbox

- https://github.com/mmbazm/device_api

- https://github.com/nqrm/sdl_docker

- https://github.com/rsys-fchaliss/hebe