CVE-2022-28470: Critical severity python package index vulnerability
Published May 8, 2022
·Updated
marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.
Affected Software
2 affected componentsFixes available
pip/marcador<0.14
0.14
Python PyPI>=0.1<=0.13
Event History
May 8, 2022
CVE Published
via MITRE·07:55 PM
Data Sourced
via MITRE·07:55 PM
Description
May 9, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID of the marcador package in PyPI?
The vulnerability ID of the marcador package in PyPI is CVE-2022-28470.
2
What is the severity of CVE-2022-28470?
The severity of CVE-2022-28470 is critical with a severity value of 9.8.
3
What is the affected software by CVE-2022-28470?
The affected software is the marcador package in PyPI versions 0.1 through 0.13.
4
Is there a code-execution backdoor in the marcador package?
Yes, the marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.
5
How can I obtain more information about CVE-2022-28470?
You can find more information about CVE-2022-28470 on the following references: - http://pypi.doubanio.com/simple/request - https://github.com/joajfreitas/marcador/issues/5 - https://pypi.org/project/marcador/