Vulnerability Description
hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hour Of Code Python 2015 Project | Hour Of Code Python 2015 | 2015-12-11 |
Related Weaknesses (CWE)
References
- https://github.com/jminh/hour_of_code_python_2015/Product
- https://github.com/jminh/hour_of_code_python_2015/issues/4ExploitIssue Tracking
- https://mirrors.neusoft.edu.cn/pypi/web/simple/request/Broken Link
- https://github.com/jminh/hour_of_code_python_2015/Product
- https://github.com/jminh/hour_of_code_python_2015/issues/4ExploitIssue Tracking
- https://mirrors.neusoft.edu.cn/pypi/web/simple/request/Broken Link
FAQ
What is CVE-2023-24107?
CVE-2023-24107 is a vulnerability with a CVSS score of 9.8 (CRITICAL). hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attac...
How severe is CVE-2023-24107?
CVE-2023-24107 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-24107?
Check the references section above for vendor advisories and patch information. Affected products include: Hour Of Code Python 2015 Project Hour Of Code Python 2015.