CVE-2022-46609
Summary
| CVE | CVE-2022-46609 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-12-14 15:15:00 UTC |
| Updated | 2022-12-16 20:41:00 UTC |
| Description | Python3-RESTfulAPI commit d9907f14e9e25dcdb54f5b22252b0e9452e3970e and e772e0beee284c50946e94c54a1d43071ca78b74 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Python3-restfulapi Project | Python3-restfulapi | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Links for request | MISC | mirrors.neusoft.edu.cn | |
| GitHub - herry-zhang/Python3-RESTfulAPI: Python3 开发以及部署 RESTful API项目(Python3 + Django2.0 + Django REST FrameWork + Centos7 + uWsgi + Nginx) | MISC | github.com | |
| Python3-RESTfulAPI/SECURITY.md at 1c2081dca357685b3180b9baeb7e761e9a10ca99 · herry-zhang/Python3-RESTfulAPI · GitHub | MISC | github.com | |
| Create SECURITY.md · herry-zhang/Python3-RESTfulAPI@1c2081d · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.