Headline
CVE-2022-44051: code execution backdoor · Issue #15 · dadadadada111/info
The d8s-stats for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-math package. The affected version of d8s-htm is 0.1.0.
We discovered a potential code execution backdoor in version 0.1.0 of the project, the backdoor is the democritus-math package. Attackers can upload democritus-math packages containing arbitrary malicious code. For the safety of this project, the democritus-math package has been uploaded by us.
The democritus-math package can be successfully installed using pip install d8s-stats==0.1.0
Suggestion: remove version 0.1.0 of this project in PyPI
PyPI address: https://pypi.org/project/d8s-stats/
Homepage address: https://github.com/democritus-project/d8s-stats