VulnerabilityModified
CVE-2022-38792
The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.
CRITICAL 9.8EPSS 1.50%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Affected
- exotel project/exotel
- Source
- cve@mitre.org
References
- https://github.com/jertel/elastalert2/pull/931Issue Tracking, Patch, Third Party Advisory
- https://github.com/sarathsp06/exotel-py/issues/10Issue Tracking, Third Party Advisory
- https://inspector.pypi.io/project/exotel/0.1.6/packages/8b/ed/9ebeb34d4adb9b01151d73ccfde9c1cb2d629c3b146953c8727559a65446/exotel-0.1.6.tar.gz/exotel-0.1.6/setup.pyThird Party Advisory
- https://pypi.org/project/exotel/Product, Third Party Advisory
- https://github.com/jertel/elastalert2/pull/931Issue Tracking, Patch, Third Party Advisory
- https://github.com/sarathsp06/exotel-py/issues/10Issue Tracking, Third Party Advisory
- https://inspector.pypi.io/project/exotel/0.1.6/packages/8b/ed/9ebeb34d4adb9b01151d73ccfde9c1cb2d629c3b146953c8727559a65446/exotel-0.1.6.tar.gz/exotel-0.1.6/setup.pyThird Party Advisory
- https://pypi.org/project/exotel/Product, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.