First published: Fri Jun 24 2022(Updated: )
The KGExplore package in PyPI v0.1.1 to v0.1.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pypi Explore | >=0.1.1<=0.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-33002 is classified as a critical severity vulnerability due to its potential for code execution and privilege escalation.
To mitigate CVE-2022-33002, upgrade the KGExplore package to a version newer than 0.1.2.
CVE-2022-33002 allows attackers to execute arbitrary code, leading to unauthorized access to sensitive information and privilege escalation.
KGExplore versions 0.1.1 and 0.1.2 are affected by CVE-2022-33002.
As of the latest reports, CVE-2022-33002 has been observed in active exploitation scenarios, emphasizing the need for immediate remediation.