CVE-2022-34054: Critical severity pypi perdido vulnerability
The Perdido package in PyPI v0.0.1 to v0.0.2 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-34054?
CVE-2022-34054 is considered a high severity vulnerability due to its potential for remote code execution and privilege escalation.
How do I fix CVE-2022-34054?
To fix CVE-2022-34054, upgrade the Perdido package to version 0.0.3 or later, which addresses the backdoor issue.
What systems are affected by CVE-2022-34054?
CVE-2022-34054 affects the Perdido package in versions 0.0.1 to 0.0.2 available on PyPI.
What are the risks associated with CVE-2022-34054?
The risks include unauthorized access to sensitive user information, digital currency keys, and potential privilege escalation.
Is there a workaround for CVE-2022-34054?
The only effective workaround for CVE-2022-34054 is to remove the affected versions of the Perdido package from your environment.