Executive brief
The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.
Affected products
- PyPI exotel
Junglewise Threat Intelligence
CVE-2022-38792 · Severity: low · CVSS 3.1 · Published 2022-08-27
Technologies: exotel (PyPI). Vendors: PyPI.
The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.