CVE-2022-40806
on github
on pypi
Published
Severity
CVSS v3:
9.8 CRITICAL
CVSS v2:
N/A
Description
The d8s-uuids for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0
References
Configurations
CPE23 | Version Start | Version End | Exact Version |
---|---|---|---|
cpe:2.3:a:democritus_uuids_project:democritus_uuids:0.1.0:*:*:*:*:python:*:* | n/a | n/a | 0.1.0 |