PT-2020-21015 · Sj-Tw-Abc · Sj-Tw-Abc

Published

2020-09-03

·

Updated

2020-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions sj-tw-abc versions (affected versions not specified)
Description The issue concerns malicious code within the sj-tw-abc package, which downloads and runs a script. This script opens a reverse shell in the system, potentially giving an outside entity full control of the computer.
Recommendations Remove the sj-tw-abc package, however, be aware that this may not remove all malicious software resulting from its installation. Consider any computer with this package installed or running as fully compromised and rotate all secrets and keys stored on it from a different computer.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-4HFC-FV33-PH9P

Affected Products

Sj-Tw-Abc