Safety vulnerability ID: 51126
The information on this page was manually curated by our Cybersecurity Intelligence Team.
D8s-netstrings 0.1.0 is vulnerable to CVE-2022-38885: It included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package.
Latest version: 0.5.2
Democritus functions for working with Netstrings.
The d8s-netstrings for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-strings package. The affected version is 0.1.0. See CVE-2022-38885.
MISC:https://github.com/democritus-project/d8s-netstrings/issues/4: https://github.com/democritus-project/d8s-netstrings/issues/4
MISC:https://pypi.org/project/d8s-netstrings/: https://pypi.org/project/d8s-netstrings/
MISC:https://pypi.org/project/democritus-strings/: https://pypi.org/project/democritus-strings/
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application