PT-2022-37338 · Pypi · Democritus-Timezones+2
Published
2022-11-07
·
Updated
2022-11-07
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
d8s-dates version 0.1.0
d8s-htm version 0.1.0
Description
A potential code-execution backdoor was inserted by a third party into the d8s-dates package for python distributed on PyPI. Another affected package is democritus-timezones.
Recommendations
For d8s-dates version 0.1.0, consider removing or avoiding the use of this version until a safe alternative is available.
For d8s-htm version 0.1.0, avoid using this version due to the potential code-execution backdoor.
As a temporary workaround, consider restricting access to the affected packages to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D8S-Dates
D8S-Htm
Democritus-Timezones