CVE-2022-32998: Critical severity cryptoasset data downloader vulnerability
The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32998?
CVE-2022-32998 is considered critical due to its potential for code execution and unauthorized access to sensitive information.
How do I fix CVE-2022-32998?
To fix CVE-2022-32998, upgrade the cryptoasset-data-downloader package to version 1.0.2 or later.
What versions are affected by CVE-2022-32998?
CVE-2022-32998 affects the cryptoasset-data-downloader package versions 1.0.0 and 1.0.1.
What type of vulnerability is CVE-2022-32998?
CVE-2022-32998 is a code execution vulnerability that enables attackers to execute arbitrary code remotely.
What impact does CVE-2022-32998 have on users?
CVE-2022-32998 allows attackers to access sensitive user information, including digital currency keys, and can lead to privilege escalation.