PT-2022-27929 · Unknown · Python3-Restfulapi

Published

2022-12-14

·

Updated

2022-12-16

·

CVE-2022-46609

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Python3-RESTfulAPI versions d9907f14e9e25dcdb54f5b22252b0e9452e3970e through e772e0beee284c50946e94c54a1d43071ca78b74
Description The issue allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges via a code execution backdoor in the request package.
Recommendations For versions d9907f14e9e25dcdb54f5b22252b0e9452e3970e through e772e0beee284c50946e94c54a1d43071ca78b74, consider disabling the request package until a patch is available. Restrict access to sensitive user information and digital currency keys to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2022-46609

Affected Products

Python3-Restfulapi