First published: Fri Jul 22 2022(Updated: )
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pypi Pypi | <=0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34500 is considered a high severity vulnerability due to its potential for code execution.
To fix CVE-2022-34500, upgrade the bin-collect package to version 0.1 or later.
CVE-2022-34500 is a code execution vulnerability resulting from a backdoor embedded in the bin-collect package.
Versions of the bin-collect package in PyPI prior to version 0.1 are vulnerable to CVE-2022-34500.
Developers and organizations using the vulnerable versions of the bin-collect package in their projects are at risk due to CVE-2022-34500.