affected: - package: ecosystem: PyPI name: watertools purl: pkg:pypi/watertools ranges: - events: - introduced: '0' type: ECOSYSTEM versions: - 0.0.1 - 0.0.10 - 0.0.11 - 0.0.19 - 0.0.2 - 0.0.20 - 0.0.21 - 0.0.22 - 0.0.23 - 0.0.25 - 0.0.26 - 0.0.27 - 0.0.28 - 0.0.29 - 0.0.3 - 0.0.30 - 0.0.31 - 0.0.32 - 0.0.33 - 0.0.36 - 0.0.37 - 0.0.38 - 0.0.39 - 0.0.4 - 0.0.40 - 0.0.41 - 0.0.42 - 0.0.43 - 0.0.44 - 0.0.45 - 0.0.46 - 0.0.47 - 0.0.5 - 0.0.6 - 0.0.7 - 0.0.8 - 0.0.9 aliases: - CVE-2022-34056 details: The Watertools package in PyPI v0.0.0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. id: PYSEC-2022-43172 modified: '2024-11-21T14:23:03.143453Z' published: '2022-06-24T21:15:00Z' references: - type: EVIDENCE url: https://github.com/TimHessels/watertools/issues/1 - type: REPORT url: https://github.com/TimHessels/watertools/issues/1 - type: WEB url: http://pypi.doubanio.com/simple/request - type: PACKAGE url: https://pypi.org/project/watertools/ severity: - score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H type: CVSS_V3 withdrawn: '2024-11-22T04:37:05Z'