Keep maintains a narrowly scoped product portfolio centered on archeevo and keep, with the durable signal concentrated in improper access controls and data exposure weakness classes. These applications present localized security concerns around files or directories accessible to external parties, and live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keep over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23377HIGH Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an attacker to retrieve local files. | Mar 1, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-30877CRITICAL The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2. | Jun 8, 2022 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keep.
Media articles that mention a CVE ID that affects a product developed by Keep — matched by CVE ID, not by vendor name.