Vulnerability Database
Blog
FAQ
Docs
CVE-2022-28470
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2022-28470
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-28470.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-28470
Aliases
GHSA-57qv-h9m7-jxfg
PYSEC-2022-185
Withdrawn
2024-05-08T06:52:26.906753Z
Published
2022-05-08T20:15:07Z
Modified
2023-11-28T23:21:18.924800Z
Severity
9.8 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Calculator
Summary
[none]
Details
marcador package in PyPI 0.1 through 0.13 included a code-execution backdoor.
References
https://github.com/joajfreitas/marcador/issues/5
https://pypi.org/project/marcador/
http://pypi.doubanio.com/simple/request
Affected packages
Git
/
github.com/joajfreitas/marcador
Affected ranges
Type
GIT
Repo
https://github.com/joajfreitas/marcador
Events
Introduced
7d20480b072109f22af199b1c1f8303f36e73c06
Affected versions
0.*
0.5.0
0.5.2
0.5.3
v0.*
v0.1
v0.2
v0.3
v0.4
CVE-2022-28470 - OSV