CVE-2023-31543
30.06.2023, 20:15
A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server.Enginsight
Vendor | Product | Version |
---|---|---|
pipreqs_project | pipreqs | 0.3.0 ≤ 𝑥 ≤ 0.4.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration