PT-2020-21310 · Leetlog · Leetlog

Published

2020-09-03

·

Updated

2020-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions leetlog versions 0.1.2 through 0.1.3
Description The issue concerns malicious code in the affected versions of leetlog, which adds an arbitrary hardcoded SSH key identified as hacker@evilmachine to the system's authorized keys. This indicates a potential compromise of the system.
Recommendations For versions 0.1.2 and 0.1.3, remove the leetlog package, but be aware that this may not remove all malicious software resulting from its installation. Consider any computer with this package installed or running as fully compromised and rotate all secrets and keys stored on it immediately from a different computer.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-GFM8-G3VM-53JH

Affected Products

Leetlog