Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-42044: code execution backdoor · Issue #4 · dadadadada111/info

The d8s-asns package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.

CVE
#git#backdoor

We discovered a potential code execution backdoor in version 0.1.0 of the project, the backdoor is the democritus-html package. Attackers can upload democritus-html packages containing arbitrary malicious code. For the safety of this project, the democritus-html package has been uploaded by us.

The democritus-html package can be successfully installed using pip install d8s-asns==0.1.0

Suggestion: remove version 0.1.0 of this project in PyPI

PyPI address: https://pypi.org/project/d8s-asns/

Homepage address: https://github.com/democritus-project/d8s-asns

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907