Remote Code Execution (RCE) Affecting ml-scanner package, versions [0,)
Threat Intelligence
EPSS
0.4% (75th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-MLSCANNER-5415004
- published 6 Apr 2023
- disclosed 6 Apr 2023
- credit Unknown
Introduced: 6 Apr 2023
CVE-2022-33000 Open this link in a new tabHow to fix?
There is no fixed version for ml-scanner
.
Overview
ml-scanner is a Scanner of ML publications
Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to using the request
package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
CVSS Scores
version 3.1