First published: Fri Jun 24 2022(Updated: )
The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pypi Perdido | >=0.0.1<=0.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34054 is considered a high severity vulnerability due to its potential for remote code execution and privilege escalation.
To fix CVE-2022-34054, upgrade the Perdido package to version 0.0.3 or later, which addresses the backdoor issue.
CVE-2022-34054 affects the Perdido package in versions 0.0.1 to 0.0.2 available on PyPI.
The risks include unauthorized access to sensitive user information, digital currency keys, and potential privilege escalation.
The only effective workaround for CVE-2022-34054 is to remove the affected versions of the Perdido package from your environment.