First published: Fri Jun 24 2022(Updated: )
The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pypi Watertools | =0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34056 is considered a critical vulnerability due to its potential for remote code execution and sensitive data exposure.
To fix CVE-2022-34056, you should upgrade to a secure version of the Watertools package as version 0.0.0 is vulnerable.
CVE-2022-34056 is a code execution backdoor vulnerability found in the Watertools package.
CVE-2022-34056 allows attackers to access sensitive user information, including digital currency keys and the ability to escalate privileges.
Any user utilizing Watertools package version 0.0.0 from PyPI is affected by CVE-2022-34056.