CVE•Published 2024-03-29•3 articles on news•5 live references•NVD data
CVE-2024-3094
Vulnerability data via CVEDB (Shodan)
CVSS v3.1
10.0
CRITICAL
EPSS percentile
100
Exploit Prediction Scoring System · top 0% of all CVEs
Description
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which is then used to modify specific functions in the liblzma code. This results in a modified liblzma library that can be used by any software linked against this library, intercepting and modifying the data interaction with this library.
Timeline
Published 2024-03-29
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
Shodan · vuln tag0 hosts
vuln:CVE-2024-3094Hosts Shodan has explicitly fingerprinted as vulnerable.
Shodan · product + version
product:"Tukaani Xz" version:"5.6.0"Version-pinned fingerprint from NVD's first vulnerable CPE.
Shodan · banner/body mention
http.html:"Xz"HTTP body or banner mentions "Xz" — catches deploys Shodan didn't identify as a product.
More intel sources (5)
Shodan report
vuln:CVE-2024-3094Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2024-3094Censys host search filtered to this CVE id.
grep.app
CVE-2024-3094Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2024-3094GitHub code search for direct mentions.
Google dork
"CVE-2024-3094" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (8)
CVE-2024-30948 repos
vulnersCom/getsploitPython
Search and download public exploits from the Vulners database — online, or fully offline from a local SQLite FTS5 index.
unipds-engenharia-de-ia-aplicada/engenharia-de-software-com-ia-aplicadaTypeScript
Códigos e referências usados na Pós de Engenharia de Software com IA Aplicada
amruth-sn/kongPython
The world's first agentic reverse engineer.
kornelski/cargo-debRust
Make Debian packages directly from Rust/Cargo projects
ulikunitz/xzGo
Pure golang package for reading and writing xz-compressed files
bureado/awesome-software-supply-chain-securityunknown
A compilation of resources in the software supply chain security domain, with emphasis on open source
morpheuslord/HackBotPython
AI-powered cybersecurity chatbot designed to provide helpful and accurate answers to your cybersecurity-related queries and also do code analysis and scan analysis.
mkbhardwas12/pwned-depsPython
Is your lockfile pwned? 5-second scan of npm/PyPI/Maven/Cargo/Go/RubyGems lockfiles for compromised packages — OSV + curated campaign feed, --min-age cooling-off gate, exit 4 when …