CVE-2022-34501: Critical severity python package index (pypi) vulnerability
Published Jul 22, 2022
·Updated
The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
Affected Software
1 affected component
PyPI PyPI<=0.1
Event History
Jul 22, 2022
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-34501?
CVE-2022-34501 is considered a critical vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2022-34501?
To mitigate CVE-2022-34501, upgrade the bin-collection package to version 0.1 or later.
3
What does CVE-2022-34501 affect?
CVE-2022-34501 affects the bin-collection package in PyPI versions before 0.1.
4
What type of vulnerability is CVE-2022-34501?
CVE-2022-34501 is a code execution backdoor vulnerability introduced by a third party.
5
Is the bin-collection package safe in versions after 0.1 regarding CVE-2022-34501?
Yes, the bin-collection package is safe in versions after 0.1 as they do not contain the backdoor.