
Cloud Vulnerability DB
A community-led vulnerabilities database
The d8s-xml Python package version 0.1.0, as distributed on PyPI, contained a potential code execution backdoor through its dependency on the democritus-strings package. The vulnerability was discovered and reported on August 27, 2022, allowing attackers to execute arbitrary malicious code through the compromised package (GitHub Issue).
The vulnerability exists in version 0.1.0 of d8s-xml through its dependency on the democritus-strings package. The backdoor mechanism allows attackers to upload malicious versions of the democritus-strings package, which could then be executed when users install d8s-xml version 0.1.0 (GitHub Issue).
The vulnerability enables attackers to execute arbitrary malicious code on systems where d8s-xml version 0.1.0 is installed, potentially leading to system compromise or unauthorized access (GitHub Issue).
Users should avoid installing version 0.1.0 of the d8s-xml package. The recommendation is to remove version 0.1.0 from PyPI to prevent further exploitation (GitHub Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."