Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cv6j-9835-p7fh

Опубликовано: 28 авг. 2022
Источник: github
Github: Прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

exotel-py includes code execution backdoor inserted by a third party

The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party. Users should downgrade to version 0.1.5 to avoid the problem.

Пакеты

Наименование

exotel

pip
Затронутые версииВерсия исправления

= 0.1.6

Отсутствует

EPSS

Процентиль: 67%
0.00549
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.

CVSS3: 9.8
nvd
больше 3 лет назад

The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.

CVSS3: 9.8
debian
больше 3 лет назад

The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code ...

EPSS

Процентиль: 67%
0.00549
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3