id: PYSEC-2023-99 modified: 2023-07-10T18:33:06.804092Z published: 2023-06-30T20:15:00Z aliases: - CVE-2023-31543 - GHSA-v4f4-23wc-99mh details: A dependency confusion in pipreqs v0.3.0 to v0.4.11 allows attackers to execute arbitrary code via uploading a crafted PyPI package to the chosen repository server. affected: - package: ecosystem: PyPI name: pipreqs purl: pkg:pypi/pipreqs ranges: - type: ECOSYSTEM events: - introduced: 0.3.0 - fixed: 0.4.12 versions: - 0.3.0 - 0.3.1 - 0.3.2 - 0.3.3 - 0.3.4 - 0.3.5 - 0.3.6 - 0.3.7 - 0.3.8 - 0.3.9 - 0.4.0 - 0.4.1 - 0.4.10 - 0.4.11 - 0.4.2 - 0.4.3 - 0.4.4 - 0.4.5 - 0.4.6 - 0.4.7 - 0.4.8 - 0.4.9 references: - type: EVIDENCE url: https://github.com/bndr/pipreqs/pull/364 - type: WEB url: https://github.com/bndr/pipreqs/pull/364 - type: FIX url: https://github.com/bndr/pipreqs/pull/364 - type: ADVISORY url: https://github.com/bndr/pipreqs/pull/364 - type: EVIDENCE url: https://gist.github.com/adeadfed/ccc834440af354a5638f889bee34bafe - type: WEB url: https://gist.github.com/adeadfed/ccc834440af354a5638f889bee34bafe - type: ADVISORY url: https://github.com/advisories/GHSA-v4f4-23wc-99mh