GHSA-2j55-pcw5-x4h2

Suggest an improvement
Source
https://github.com/advisories/GHSA-2j55-pcw5-x4h2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-2j55-pcw5-x4h2/GHSA-2j55-pcw5-x4h2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2j55-pcw5-x4h2
Aliases
  • CVE-2018-3779
Published
2018-08-13T15:02:49Z
Modified
2023-11-08T04:00:19.936014Z
Summary
active-support impersonates 'activesupport' gem
Details

The active-support ruby gem gem is malware and duplicates the official activesupport (no hyphen) gem, but adds a compiled extension. The extension attempts to resolve a base64 encoded domain (29faea63.planfhntage.de), downloads a payload, and executes.

This trojan horse gem could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system. No version of this gem should be considered safe.

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [
        "CWE-77"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T20:52:19Z"
}
References

Affected packages

RubyGems / active-support

Package

Name
active-support
Purl
pkg:gem/active-support

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected