CVE-2022-33000
EPSS 0.44%
Description
The ML-Scanner package in PyPI v0.1.0 to v0.1.5 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
How to fix CVE-2022-33000
To remediate CVE-2022-33000, upgrade the affected package to a fixed version below.
- PyPI/ml-scanner—upgrade to 0.1.7 or later
Is CVE-2022-33000 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 0.1.0, < 0.1.7