PT-2022-21997 · Unknown · Rondolu-Yt-Concate

Di1L0O

·

Published

2022-06-24

·

Updated

2022-07-06

·

CVE-2022-34065

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rondolu-YT-Concate version 0.1.0
Description The issue concerns a code execution backdoor in the Rondolu-YT-Concate package. This backdoor allows attackers to access sensitive user information, including digital currency keys, and escalate privileges.
Recommendations For version 0.1.0, consider removing or avoiding the use of the Rondolu-YT-Concate package until a secure version is available. As a temporary workaround, restrict access to sensitive information and monitor for any suspicious activity that may indicate exploitation of this backdoor.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-34065

Affected Products

Rondolu-Yt-Concate