First published: Fri Jun 24 2022(Updated: )
The Beginner package in PyPI v0.0.2 to v0.0.4 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pypi Beginner | >=0.0.2<=0.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-33004 is classified as a critical vulnerability due to its potential for code execution and the exposure of sensitive user information.
To fix CVE-2022-33004, upgrade the Beginner package to version 0.0.5 or later, which addresses this vulnerability.
CVE-2022-33004 affects versions 0.0.2 to 0.0.4 of the Beginner package.
CVE-2022-33004 is a code execution backdoor vulnerability that can lead to unauthorized access and privilege escalation.
Users and developers who utilize the Beginner package in their applications are primarily impacted by CVE-2022-33004.