PT-2022-37347 · Unknown+2 · Democritus-Algorithms+2
Published
2022-11-07
·
Updated
2022-11-07
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
d8s-htm version 0.1.0
democritus-algorithms (affected versions not specified)
Description
A potential code-execution backdoor was inserted by a third party into the d8s-python package distributed on PyPI. The democritus-algorithms package also contains a potential code execution backdoor inserted by third parties.
Recommendations
For d8s-htm version 0.1.0, update to a version that does not include the backdoor.
For democritus-algorithms, avoid using the package until the issue is resolved.
As a temporary workaround, consider restricting access to the affected packages to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D8S-Htm
D8S-Python
Democritus-Algorithms