CVE-2022-34500: Critical severity python package index (pypi) vulnerability
Published Jul 22, 2022
·Updated
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
Affected Software
1 affected component
PyPI PyPI<=0.1
Event History
Jul 22, 2022
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-34500?
CVE-2022-34500 is considered a high severity vulnerability due to its potential for code execution.
2
How do I fix CVE-2022-34500?
To fix CVE-2022-34500, upgrade the bin-collect package to version 0.1 or later.
3
What kind of vulnerability is CVE-2022-34500?
CVE-2022-34500 is a code execution vulnerability resulting from a backdoor embedded in the bin-collect package.
4
Which versions of the affected software are vulnerable to CVE-2022-34500?
Versions of the bin-collect package in PyPI prior to version 0.1 are vulnerable to CVE-2022-34500.
5
Who is affected by CVE-2022-34500?
Developers and organizations using the vulnerable versions of the bin-collect package in their projects are at risk due to CVE-2022-34500.