First published: Tue Oct 11 2022(Updated: )
The d8s-xml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-html package. The affected version is 0.1.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
D8s-xml | =0.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42043 refers to a vulnerability in the d8s-xml package for Python where a potential code-execution backdoor was inserted by a third party.
The severity of CVE-2022-42043 is critical with a CVSS score of 9.8.
The affected software is the d8s-xml package for Python version 0.1.0.
To fix CVE-2022-42043, update the d8s-xml package for Python to a version that does not include the democritus-html package.
You can find more information about CVE-2022-42043 at the following references: [Link 1](https://github.com/dadadadada111/info/issues/5), [Link 2](https://pypi.org/project/d8s-xml/), [Link 3](https://pypi.org/project/democritus-html/).