GHSA-333g-rpr4-7hxq

Source
https://github.com/advisories/GHSA-333g-rpr4-7hxq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/08/GHSA-333g-rpr4-7hxq/GHSA-333g-rpr4-7hxq.json
Aliases
  • CVE-2019-15224
Published
2019-08-20T14:29:03Z
Modified
2024-02-16T08:10:46.997001Z
Details

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Users of an affected version should consider downgrading to the last non-affected version of 1.6.9, or upgrading to 1.7.x. Additionally, a set of other minor gems have been partially or completely yanked and are included in this advisory. These include cronparser, coinbase, blockchainwallet, awesome-bot, doge-coin, capistrano-colors, bitcoinvanity, litacoin, coming-soon, and omniauthamazon.

References

Affected packages

RubyGems / rest-client

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.6.10
Fixed
1.7.0

Affected versions

1.*

1.6.14
1.7.0.rc1

Database specific

{
    "last_known_affected_version_range": "<= 1.6.13"
}

RubyGems / cron_parser

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.13
Last affected
1.0.14

RubyGems / cron_parser

Package

Affected ranges

Affected versions

0.*

0.1.4

RubyGems / coin_base

Package

Name
coin_base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown

RubyGems / blockchain_wallet

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown

RubyGems / awesome-bot

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown

RubyGems / doge-coin

Package

Name
doge-coin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown

RubyGems / capistrano-colors

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown

RubyGems / bitcoin_vanity

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown

RubyGems / coming-soon

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown

RubyGems / omniauth_amazon

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown