Junglewise Threat Intelligence
CVE-2022-41380: PYSEC-2022-43039 - The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoo
CVE-2022-41380 · Severity: info · Published 2022-10-11
Technologies: democritus-file-system (PyPI). Vendors: PyPI.
Executive brief
The d8s-yaml package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-file-system package. The affected version is 0.1.0.
Affected products
- PyPI democritus-file-system
- PyPI d8s-yaml
Related threats
- PYSEC-2022-43041 - The d8s-json package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoo
- PYSEC-2022-43040 - The d8s-utility package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The back
- PYSEC-2022-43042 - The d8s-archives package for Python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The bac
- PYSEC-2022-43099 - The d8s-pdfs for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the
- PYSEC-2022-43098 - The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the