Code Execution Vulnerability in ML-Scanner Package by PyPI
CVE-2022-33000

9.8CRITICAL

Key Information:

Vendor

Pypi

Vendor
CVE Published:
24 June 2022

What is CVE-2022-33000?

The ML-Scanner package in PyPI versions 0.1.0 to 0.1.5 is susceptible to a code execution backdoor due to vulnerabilities in the request package. This flaw enables malicious actors to execute arbitrary code, potentially compromising sensitive user data, including user credentials and digital currency keys. Additionally, there are risks of privilege escalation, increasing the severity of the potential impact on systems utilizing this package.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.