PT-2020-20950 · Rrgod · Rrgod
Published
2020-09-02
·
Updated
2020-09-02
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
rrgod versions all
Description
The issue concerns a malicious package designed to execute arbitrary scripts. When installed, it downloads and executes an arbitrary file as pre, post, and install scripts.
Recommendations
For all versions, consider the system compromised if this package is found, and assess if further response, such as rotating all credentials found on the compromised machine, is necessary.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rrgod