PT-2022-21636 · Pypi · Request+1

Di1L0O

·

Published

2022-06-24

·

Updated

2022-07-05

·

CVE-2022-33001

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AAmiles package in PyPI version 0.1.0
Description The issue allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges, via a code execution backdoor in the request package.
Recommendations For AAmiles package in PyPI version 0.1.0, consider removing or avoiding the use of this version until a fixed version is available. As a temporary workaround, consider disabling the request package functionality until a patch is available. Restrict access to sensitive user information and digital currency keys to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-33001

Affected Products

Aamiles
Request