Bugzilla – Bug 1212933
VUL-0: CVE-2023-31543: python-pipreqs: dependency confusion allows attackers to execute arbitrary code via uploading a crafted PyPI package
Last modified: 2024-06-07 12:20:43 UTC
CVE-2023-31543 A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31543 https://www.cve.org/CVERecord?id=CVE-2023-31543 https://gist.github.com/adeadfed/ccc834440af354a5638f889bee34bafe https://github.com/bndr/pipreqs/pull/364
affects Factory and Backports
This is an autogenerated message for OBS integration: This bug (1212933) was mentioned in https://build.opensuse.org/request/show/1097856 Factory / python-pipreqs
This is an autogenerated message for OBS integration: This bug (1212933) was mentioned in https://build.opensuse.org/request/show/1098582 Backports:SLE-15-SP4 / python-pipreqs
fix for openSUSE:Backports:SLE-15-SP5:Update/python-pipreqs also needed
This is an autogenerated message for OBS integration: This bug (1212933) was mentioned in https://build.opensuse.org/request/show/1099186 Backports:SLE-15-SP5 / python-pipreqs
All done, closing.