First published: Sun May 08 2022(Updated: )
marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Python PyPI | >=0.1<=0.13 | |
pip/marcador | <0.14 | 0.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of the marcador package in PyPI is CVE-2022-28470.
The severity of CVE-2022-28470 is critical with a severity value of 9.8.
The affected software is the marcador package in PyPI versions 0.1 through 0.13.
Yes, the marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.
You can find more information about CVE-2022-28470 on the following references: - http://pypi.doubanio.com/simple/request - https://github.com/joajfreitas/marcador/issues/5 - https://pypi.org/project/marcador/