{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_informational_advisory","csaf_version":"2.1","title":"XZ Utils supply chain compromise (CVE-2024-3094)","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2024-00007","status":"final","version":"24","initial_release_date":"2024-04-04T12:34:31+00:00","current_release_date":"2026-08-18T21:54:22.819188+00:00","revision_history":[{"date":"2024-04-04T12:34:31+00:00","number":"24","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2024-00007"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2024-3094"}],"notes":[{"category":"summary","text":"On March 29, a software engineer at Microsoft discovered and disclosed a supply chain attack against the popular Linux decompression utility XZ Utils. After analysis, researchers confirmed a rogue developer had inserted malicious code into the 5.6.0 and 5.6.1 releases of XZ Utils. This malicious code could allow an adversary with a carefully crafted SSH public key to execute arbitrary code with SYSTEM permissions on affected Linux-based systems.\n\nNo WatchGuard products use the affected versions of XZ Utils","title":"Summary"}]}}