Skip to content
This repository has been archived by the owner on Mar 15, 2024. It is now read-only.

Antilles Dependency Confusion Vulnerability

High
yixuan178 published GHSA-hgc3-hp6x-wpgx Nov 3, 2021

Package

pip antilles-tools (pip)

Affected versions

1.0.0

Patched versions

1.0.1

Description

Potential Impact:

Remote code execution

Scope of Impact:

Open-source project specific

Summary Description:

A dependency confusion vulnerability was reported in the Antilles open-source software prior to version 1.0.1 that could allow for remote code execution during installation due to a package listed in requirements.txt not existing in the public package index (PyPi).
MITRE classifies this weakness as an Uncontrolled Search Path Element (CWE-427) in which a private package dependency may be replaced by an unauthorized package of the same name published to a well-known public repository such as PyPi.
The configuration has been updated to only install components built by Antilles, removing all other public package indexes. Additionally, the antilles-tools dependency has been published to PyPi.

Mitigation Strategy for Customers (what you should do to protect yourself):

Remove previous versions of Antilles as a precautionary measure and Update to version 1.0.1 or later.

Acknowledgement:

The Antilles team thanks Kotko Vladyslav for reporting this issue.

References:

c7b9c57

Severity

High

CVE ID

CVE-2021-3840

Weaknesses

No CWEs