PT-2022-21997 · Unknown · Rondolu-Yt-Concate
Di1L0O
·
Published
2022-06-24
·
Updated
2022-07-06
·
CVE-2022-34065
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rondolu-YT-Concate version 0.1.0
Description
The issue concerns a code execution backdoor in the Rondolu-YT-Concate package. This backdoor allows attackers to access sensitive user information, including digital currency keys, and escalate privileges.
Recommendations
For version 0.1.0, consider removing or avoiding the use of the Rondolu-YT-Concate package until a secure version is available. As a temporary workaround, restrict access to sensitive information and monitor for any suspicious activity that may indicate exploitation of this backdoor.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rondolu-Yt-Concate