Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-35p8-rgfh-rpw2

Опубликовано: 22 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.

hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.

EPSS

Процентиль: 37%
0.00156
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
почти 3 года назад

hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.

EPSS

Процентиль: 37%
0.00156
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94