CVE-2021-3572
MediumAdvisory
Published 10 Nov 2021In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.7
- base score, highest
- EPSS
- 0.018
- 78th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 376
- of 17,781 indexed, latest versions
- Container images
- 377
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Improper Input Validation in pip
Carried by container images the latest versions of 376 of 17,781 indexed charts deploy, on 377 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pippypi | 1.5.4, 8.1.1, 8.1.2, 9.0.0+27 more | 21.1 | 365 |
| python-pipdeb | 1.5.4-1ubuntu4, 8.1.1-2ubuntu0.4, 9.0.1-2.3~ubuntu1, 9.0.1-2.3~ubuntu1.18.04.1+3 more | 1.5.4-1ubuntu4+esm1, 8.1.1-2ubuntu0.6+esm2, 9.0.1-2.3~ubuntu1.18.04.5+esm2 | 27 |
| python-piprpm | 9.0.3-15.el8, 9.0.3-16.el8, 9.0.3-18.el8, 9.0.3-19.el8 | 0:9.0.3-20.el8 | 35 |
- OSV records
- GHSA-5xp3-jfq3-5q8xRHSA-2021:4455UBUNTU-CVE-2021-3572
- Also known as
- PYSEC-2021-437, USN-4961-2
Charts affected
376 by stars
Container images carrying it
377 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| octoprint/ | 106c26efcd8a | pip | 21.1 | 1 |
| odaniait/ | 3fff8a8570ec | pip | 21.1 | 1 |
| omecproject/ | bcc5f19fd676 | pip python-pip | 21.1 9.0.1-2.3~ubuntu1.18.04.5+esm2 | 1 |
| omecproject/ | d109a8e57e71 | pip python-pip | 21.1 8.1.1-2ubuntu0.6+esm2 | 1 |
| opendatacube/ | 5d810e8504b8 | pip python-pip | 21.1 9.0.1-2.3~ubuntu1.18.04.5+esm2 | 1 |
| opendatacube/ | 91870111837c | pip python-pip | 21.1 9.0.1-2.3~ubuntu1.18.04.5+esm2 | 1 |
| opendatacube/ | 1b90cdf68831 | pip python-pip | 21.1 9.0.1-2.3~ubuntu1.18.04.5+esm2 | 1 |
| openelevation/ | 82fb21612e86 | pip | 21.1 | 1 |
| openwhisk/ | 63dc3d2a0904 | pip | 21.1 | 1 |
| openwhisk/ | c80dba0de3aa | pip python-pip | 21.1 9.0.1-2.3~ubuntu1.18.04.5+esm2 | 1 |
| pecan/ | 73b2074f3fec | pip | 21.1 | 1 |
| phntom/ | d2b844700b57 | pip | 21.1 | 1 |
| pnnlmiscscripts/ | 155131891741 | pip python-pip | 21.1 0:9.0.3-20.el8 | 1 |
| pnnlmiscscripts/ | 8af4b7551d40 | pip | 21.1 | 1 |
| prompve/ | ff6749eb03b0 | pip | 21.1 | 1 |
| pypiserver/ | c9250d3c418d | pip | 21.1 | 1 |
| redash/ | 9392753c0376 | pip | 21.1 | 1 |
| rezachalak/ | 34f694325191 | pip | 21.1 | 1 |
| rhasspy/ | 80b99ddeef6c | pip | 21.1 | 1 |
| richardchesterwood/ | ed7d720878ac | pip | 21.1 | 1 |
| roadiehq/ | ef355bf5b639 | pip | 21.1 | 1 |
| samueldg/ | 3987195edbe6 | pip | 21.1 | 1 |
| scrapinghub/ | a5f89bc84606 | pip python-pip | 21.1 9.0.1-2.3~ubuntu1.18.04.5+esm2 | 1 |
| seafileltd/ | 6693911bcc40 | pip | 21.1 | 1 |
| seafileltd/ | 70628f29c663 | pip | 21.1 | 1 |
| seafileltd/ | 7ac833196f60 | pip | 21.1 | 1 |
| seafileltd/ | ed0fcda5e6a9 | pip | 21.1 | 1 |
| seldonio/ | 1d0da98a2d76 | pip python-pip | 21.1 8.1.1-2ubuntu0.6+esm2 | 1 |
| seldonio/ | 4e985d2006a8 | pip python-pip | 21.1 0:9.0.3-20.el8 | 1 |
| skylenet/ | 210353ce7c89 | pip | 21.1 | 1 |
| socialmediamacroscope/ | 70fb11d4f531 | pip | 21.1 | 1 |
| socialmediamacroscope/ | 19d3d26d53ee | pip | 21.1 | 1 |
| socialmediamacroscope/ | f508216be63c | pip | 21.1 | 1 |
| softonic/ | a64d6c0e0ae5 | pip | 21.1 | 1 |
| softonic/ | d9487a8dd70f | pip | 21.1 | 1 |
| someblackmagic/ | 6eca64b6b440 | pip | 21.1 | 1 |
| stackstorm/ | 88235ba70cad | pip | 21.1 | 1 |
| stackstorm/ | 6f56d239d280 | pip | 21.1 | 1 |
| stackstorm/ | 33ecfda16608 | pip | 21.1 | 1 |
| stackstorm/ | 4e3f8c7ca52d | pip | 21.1 | 1 |
| stackstorm/ | f190a6212195 | pip | 21.1 | 1 |
| stackstorm/ | 259503496ff9 | pip | 21.1 | 1 |
| stackstorm/ | b1de2055c362 | pip | 21.1 | 1 |
| stackstorm/ | b1a338f64773 | pip | 21.1 | 1 |
| stackstorm/ | 1c8904a3bf67 | pip | 21.1 | 1 |
| stackstorm/ | 1bf35bfaf00c | pip | 21.1 | 1 |
| stackstorm/ | 19fdfffdbba8 | pip | 21.1 | 1 |
| stakater/ | a47e96ebb285 | pip | 21.1 | 1 |
| stakater/ | 4f8e409f30c2 | pip | 21.1 | 1 |
| stakewiselabs/ | 2afd0c0b34cb | pip | 21.1 | 1 |