Remote Code Execution Vulnerability in Beginner Package from PyPI
CVE-2022-33004
9.8CRITICAL
What is CVE-2022-33004?
The Beginner package from PyPI, specifically versions 0.0.2 through 0.0.4, has been found to contain a significant vulnerability that allows for remote code execution. This flaw, attributed to a compromised 'request' package, enables unauthorized attackers to execute arbitrary code. As a consequence, attackers can potentially gain access to sensitive user information, including personal data and digital currency keys, and may escalate their privileges within a compromised system.
