PT-2022-3393 · Pypi · Keep+1

·

CVE-2022-30877

·

Published

2022-06-08

·

Updated

2023-08-08

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions keep versions prior to 1.2
Description The issue is related to a code-execution backdoor inserted by a third party in the keep package for Python. This backdoor is associated with a malicious dependency named request. Exploitation of this issue may allow a remote attacker to execute arbitrary code.
Recommendations For versions prior to 1.2, update to version 1.2 to resolve the issue. As a temporary workaround, consider avoiding the use of the request dependency until the issue is resolved.

Exploit

Fix

Hidden Functionality

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04165
CVE-2022-30877
PYSEC-2022-43056

Affected Products

Keep
Request