GHSA-333g-rpr4-7hxq

Suggest an improvement
Source
https://github.com/advisories/GHSA-333g-rpr4-7hxq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/08/GHSA-333g-rpr4-7hxq/GHSA-333g-rpr4-7hxq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-333g-rpr4-7hxq
Aliases
  • CVE-2019-15224
Published
2019-08-20T14:29:03Z
Modified
2024-02-16T08:10:46.997001Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
rest-client Gem Contains Malicious Code
Details

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Users of an affected version should consider downgrading to the last non-affected version of 1.6.9, or upgrading to 1.7.x. Additionally, a set of other minor gems have been partially or completely yanked and are included in this advisory. These include cronparser, coinbase, blockchainwallet, awesome-bot, doge-coin, capistrano-colors, bitcoinvanity, litacoin, coming-soon, and omniauthamazon.

Database specific
{
    "nvd_published_at": "2019-08-19T23:15:00Z",
    "cwe_ids": [
        "CWE-94"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2019-08-20T14:27:19Z"
}
References

Affected packages

RubyGems / rest-client

Package

Name
rest-client
Purl
pkg:gem/rest-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.6.10
Fixed
1.7.0

Affected versions

1.*

1.6.14
1.7.0.rc1

Database specific

{
    "last_known_affected_version_range": "<= 1.6.13"
}

RubyGems / cron_parser

Package

Name
cron_parser
Purl
pkg:gem/cron_parser

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.13
Last affected
1.0.14

RubyGems / cron_parser

Package

Name
cron_parser
Purl
pkg:gem/cron_parser

Affected ranges

Affected versions

0.*

0.1.4

RubyGems / coin_base

Package

Name
coin_base
Purl
pkg:gem/coin_base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

RubyGems / blockchain_wallet

Package

Name
blockchain_wallet
Purl
pkg:gem/blockchain_wallet

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

RubyGems / awesome-bot

Package

Name
awesome-bot
Purl
pkg:gem/awesome-bot

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

RubyGems / doge-coin

Package

Name
doge-coin
Purl
pkg:gem/doge-coin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

RubyGems / capistrano-colors

Package

Name
capistrano-colors
Purl
pkg:gem/capistrano-colors

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

RubyGems / bitcoin_vanity

Package

Name
bitcoin_vanity
Purl
pkg:gem/bitcoin_vanity

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

RubyGems / coming-soon

Package

Name
coming-soon
Purl
pkg:gem/coming-soon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

RubyGems / omniauth_amazon

Package

Name
omniauth_amazon
Purl
pkg:gem/omniauth_amazon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected