PYSEC-2023-99

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/pipreqs/PYSEC-2023-99.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/PYSEC-2023-99
Aliases
Published
2023-06-30T20:15:00Z
Modified
2023-11-01T05:02:01.010525Z
Summary
[none]
Details

A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server.

References

Affected packages

PyPI / pipreqs

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.3.0
Fixed
0.4.12

Affected versions

0.*

0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
0.4.10
0.4.11