PT-2022-37347 · Unknown+2 · Democritus-Algorithms+2

Published

2022-11-07

·

Updated

2022-11-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions d8s-htm version 0.1.0 democritus-algorithms (affected versions not specified)
Description A potential code-execution backdoor was inserted by a third party into the d8s-python package distributed on PyPI. The democritus-algorithms package also contains a potential code execution backdoor inserted by third parties.
Recommendations For d8s-htm version 0.1.0, update to a version that does not include the backdoor. For democritus-algorithms, avoid using the package until the issue is resolved. As a temporary workaround, consider restricting access to the affected packages to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

PYSEC-2022-43084

Affected Products

D8S-Htm
D8S-Python
Democritus-Algorithms