CVE-2022-33000: Critical severity pypi ml-scanner vulnerability
The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-33000?
CVE-2022-33000 has been categorized as a critical vulnerability due to its potential for remote code execution and data exposure.
How do I fix CVE-2022-33000?
To fix CVE-2022-33000, it is recommended to upgrade to a version of the ML-Scanner package that is greater than 0.1.5.
What types of information are at risk with CVE-2022-33000?
CVE-2022-33000 exposes sensitive user information including digital currency keys and allows privilege escalation.
Which versions of ML-Scanner are affected by CVE-2022-33000?
CVE-2022-33000 affects all versions of the ML-Scanner package from 0.1.0 to 0.1.5.
What is ML-Scanner in relation to CVE-2022-33000?
ML-Scanner is a package available on PyPI that contains a vulnerability allowing code execution through a backdoor in specific versions.