Appearance
MET-2024-001
XZ Utils (CVE-2024-3094)
Appearance
XZ Utils (CVE-2024-3094)
| Bulletin ID | MET-2024-001 |
|---|---|
| Date (published) | 2024-04-02T00:00:00.000Z |
| Date (last updated) | 2024-04-02T00:00:00.000Z |
| Severity | Informational |
On March 29th, 2024, malicious code was discovered in XZ Utils, a compression tool, versions 5.6.0 and 5.6.1. The vulnerability could have been used to target SSH and allow a malicious actor to gain access to vulnerable Linux hosts.
Metaplay infrastructure and product are not affected by this vulnerability.
mcr.microsoft.com/dotnet/aspnet images (as of present tag 8.0), which do not contain the tool or libraries.None.
Security-related questions or concerns can be sent to security@metaplay.io.
| Date | Description |
|---|---|
| 2024-04-02 | Security Bulletin released |