CVE-2023-24107 Information

Description

hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.

Reference

https://github.com/jminh/hour_of_code_python_2015/ https://mirrors.neusoft.edu.cn/pypi/web/simple/request/ https://github.com/jminh/hour_of_code_python_2015/issues/4

Share on: