{"id":"GSD-2022-1002521","summary":"backdoor in ctx version 0.1.2-1, 0.1.2-2, 0.1.4, 0.2, 0.2.1, 0.2.2, 0.2.2.1, 0.2.3, 0.2.4, 0.2.5, 0.2.6","details":"In PyPI ctx version 0.1.2-1, 0.1.2-2, 0.1.4, 0.2, 0.2.1, 0.2.2, 0.2.2.1, 0.2.3, 0.2.4, 0.2.5, 0.2.6 a backdoor exists in the ctx package that can be attacked via a malicious package update resulting in credential theft from environment variables","aliases":["PYSEC-2022-199"],"modified":"2023-11-08T04:24:37.303329Z","published":"2022-05-24T16:49:59.126662Z","withdrawn":"2023-03-14T07:01:09.291593Z","references":[{"type":"WEB","url":"https://isc.sans.edu/diary/28678"},{"type":"WEB","url":"https://blog.sonatype.com/pypi-package-ctx-compromised-are-you-at-risk"},{"type":"WEB","url":"https://github.com/github/advisory-database/issues/325"},{"type":"ARTICLE","url":"https://python-security.readthedocs.io/pypi-vuln/index-2022-05-24-ctx-domain-takeover.html"},{"type":"ADVISORY","url":"https://github.com/pypa/advisory-database/blob/main/vulns/ctx/PYSEC-2022-199.yaml"}],"schema_version":"1.7.3"}