Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2024-3094] Backdoor in XZ Utils allows RCE: everything you need to know

wiz.io | vulnerability | CVE-2024-3094 | #cloud | #rce | #supply-chain | #linux | #vulnerability | #backdoor | #xz-utils | #cve-2024-3094

Summary

Wiz explains CVE-2024-3094, the XZ Utils backdoor in versions 5.6.0 and 5.6.1 that could enable SSH authentication bypass and RCE on certain distros; about 2% of cloud environments were affected.
Published
Collected

original ↗

Related coverage

back