PYSEC-2022-220

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/pyesasky/PYSEC-2022-220.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2022-220
Aliases
  • CVE-2022-30885
Published
2022-06-24T21:15:00Z
Modified
2023-11-08T04:09:20.276157Z
Summary
[none]
Details

** Reserved ** The pyesasky for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.0-1.4.2.

References

Affected packages

PyPI / pyesasky

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.2.0
Fixed
1.4.3

Affected versions

1.*
1.2.0
1.2.1
1.2.2
1.2.4
1.2.5
1.2.6
1.2.7
1.2.11
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.4.0
1.4.1b0
1.4.1
1.4.2

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/pyesasky/PYSEC-2022-220.yaml"