
Cloud Vulnerability DB
A community-led vulnerabilities database
The d8s-dates Python package version 0.1.0, as distributed on PyPI, contained a code-execution backdoor that was inserted by a third party (NVD). The vulnerability was discovered and disclosed on September 14, 2022. The backdoor was implemented through a malicious dependency called democritus-hypothesis package (GitHub Issue).
The vulnerability existed in version 0.1.0 of the d8s-dates package. The backdoor was implemented through a compromised dependency package called democritus-hypothesis, which could be installed when users installed d8s-dates using the command 'pip install d8s-dates==0.1.0'. This allowed potential attackers to execute arbitrary malicious code through the compromised package (GitHub Issue).
The vulnerability allowed attackers to execute arbitrary code on systems where the affected version of d8s-dates was installed. This could potentially lead to unauthorized access to sensitive information, system compromise, and further exploitation of the affected systems (NVD).
Users should avoid using version 0.1.0 of the d8s-dates package. The recommendation is to remove version 0.1.0 from PyPI to prevent further installations of the compromised package (GitHub Issue).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."