PT-2022-21639 · Pypi · Beginner+1

Di1L0O

·

Published

2022-06-24

·

Updated

2022-07-05

·

CVE-2022-33004

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Beginner package in PyPI versions 0.0.2 through 0.0.4
Description The issue allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges via a code execution backdoor in the request package.
Recommendations For versions 0.0.2 through 0.0.4, consider removing or updating the affected package to prevent exploitation. As a temporary workaround, restrict the use of the request package until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-33004
PYSEC-2022-214

Affected Products

Beginner
Request