CVE-2022-38885

Published
View on NVD ↗
CVSS v3
9.8
CRITICAL
CVSS v2
N/A
Affected
3
PROJECTS

Description

The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.

Democritus functions for working with Python strings.
Python Package IndexPython Package Index
Democritus functions for working with Netstrings.
Python Package IndexPython Package Index
Democritus functions for working with Netstrings.
GitHubGitHub