PT-2020-21086 · Unknown · Malicious-Do-Not-Install

Published

2020-09-03

·

Updated

2020-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions malicious-do-not-install (affected versions not specified)
Description The issue concerns malicious code in the software that copies sensitive files, specifically /etc/passwd and /etc/shadow, to the local /tmp/ folder. This action compromises system security by potentially exposing user credentials.
Recommendations Remove the malicious-do-not-install package from your environment and rotate affected credentials.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-6879-XR95-5GF4

Affected Products

Malicious-Do-Not-Install