
Cloud Vulnerability DB
A community-led vulnerabilities database
The d8s-netstrings package for Python version 0.1.0, as distributed on PyPI, contained a potential code-execution backdoor that was inserted by a third party. The backdoor was implemented through the democritus-strings package dependency (GitHub Issue, CISA Bulletin).
The vulnerability, identified as CVE-2022-38885, was discovered in version 0.1.0 of the d8s-netstrings package. The security issue stems from a malicious dependency package (democritus-strings) that could allow attackers to execute arbitrary code through the compromised package (GitHub Issue).
The vulnerability allows attackers to potentially execute arbitrary malicious code through the compromised package when it is installed using the command 'pip install d8s-netstrings==0.1.0' (GitHub Issue).
Users should avoid using version 0.1.0 of the d8s-netstrings package. The recommendation is to remove version 0.1.0 from PyPI to prevent further exploitation (GitHub Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."