First published: Mon Sep 19 2022(Updated: )
The d8s-archives for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D8s-archives | =0.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38881 is considered high severity due to its potential for arbitrary code execution.
CVE-2022-38881 affects version 0.1.0 of the d8s-archives package.
To fix CVE-2022-38881, you should remove the d8s-archives package version 0.1.0 and update to a secure version.
If you have d8s-archives version 0.1.0 installed, immediately uninstall it to prevent any potential security risks.
The backdoor in CVE-2022-38881 was inserted by a third party into the democritus-strings package.