{"id":"UBUNTU-CVE-2022-2054","details":"Code Injection in GitHub repository nuitka/nuitka prior to 0.9.","modified":"2026-05-20T16:07:35.144360550Z","published":"2022-06-12T14:15:00Z","upstream":["CVE-2022-2054"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-2054"},{"type":"REPORT","url":"https://huntr.dev/bounties/ea4a842c-c48c-4aae-a599-3305125c63a7/"},{"type":"REPORT","url":"https://github.com/nuitka/nuitka/commit/09647745d7cbb6ff32f9fa948f19d5558b32bcad"},{"type":"REPORT","url":"https://huntr.dev/bounties/ea4a842c-c48c-4aae-a599-3305125c63a7"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-2054"}],"affected":[{"package":{"name":"nuitka","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/nuitka?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.5.13+ds-1","0.5.15+ds-1","0.5.16+ds-1","0.5.16.1+ds-1","0.5.17+ds-1","0.5.18.1+ds-1","0.5.21.2+ds-1~16.04"],"ecosystem_specific":{"binaries":[{"binary_version":"0.5.21.2+ds-1~16.04","binary_name":"nuitka"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-2054.json"}},{"package":{"name":"nuitka","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/nuitka?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.5.27+ds-1","0.5.28.1+ds-1","0.5.28.2+ds-1"],"ecosystem_specific":{"binaries":[{"binary_name":"nuitka","binary_version":"0.5.28.2+ds-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-2054.json"}},{"package":{"name":"nuitka","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/nuitka?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.6.11.3+ds-1.2","0.6.11.3+ds-1.2build2","0.6.17.2+ds-1","0.6.17.2+ds-1.1","0.6.18.5+ds-1","0.6.18.6+ds-1","0.6.19.1+ds-1"],"ecosystem_specific":{"binaries":[{"binary_name":"nuitka","binary_version":"0.6.19.1+ds-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-2054.json"}},{"package":{"name":"nuitka","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/nuitka?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.5+ds-1"],"ecosystem_specific":{"binaries":[{"binary_name":"nuitka","binary_version":"1.3.5+ds-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-2054.json"}},{"package":{"name":"nuitka","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/nuitka?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.5+ds-1"],"ecosystem_specific":{"binaries":[{"binary_name":"nuitka","binary_version":"1.3.5+ds-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-2054.json"}},{"package":{"name":"nuitka","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/nuitka?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.3.5+ds-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.3.5+ds-1","binary_name":"nuitka"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-2054.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}