sonatype-2023-3387 | Security Details | Sonatype Guide

sonatype-2023-3387

VMConnect at 28 July 2023 - Malicious Package ("PaperPin" campaign)

Published Jul 28, 2023

CVSS Score: Critical 10.0

Security Details

Components Impacted

sonatype-2023-3387 Security Details

CVE ID: sonatype-2023-3387
CWE: N/A
CVE Description: VMConnect at 28 July 2023 - Malicious Package ("PaperPin" campaign)
Published: Jul 28, 2023

CVSS Score & Severity

10.0 Critical
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score: 0%

Malware

malware

KEV Status

Not in KEV Catalog: No known exploits

Affected Ecosystems

affected

Source: Sonatype

References