affected: - package: ecosystem: PyPI name: drxhello purl: pkg:pypi/drxhello ranges: - events: - introduced: '0' type: ECOSYSTEM versions: - 0.0.1 - 0.0.2 aliases: - CVE-2022-34055 details: The drxhello package in PyPI v0.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. id: PYSEC-2022-43133 modified: '2024-11-21T14:22:45.663614Z' published: '2022-06-24T21:15:00Z' references: - type: WEB url: http://pypi.doubanio.com/simple/request - type: EVIDENCE url: https://github.com/drewxa/summer-tasks/issues/4 - type: REPORT url: https://github.com/drewxa/summer-tasks/issues/4 - type: PACKAGE url: https://pypi.org/project/drxhello/ severity: - score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H type: CVSS_V3 withdrawn: '2024-11-22T04:37:03Z'