First published: Fri Jul 22 2022(Updated: )
The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pypi Pypi | <=0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34501 is considered a critical vulnerability due to the potential for remote code execution.
To mitigate CVE-2022-34501, upgrade the bin-collection package to version 0.1 or later.
CVE-2022-34501 affects the bin-collection package in PyPI versions before 0.1.
CVE-2022-34501 is a code execution backdoor vulnerability introduced by a third party.
Yes, the bin-collection package is safe in versions after 0.1 as they do not contain the backdoor.