GHSA-333g-rpr4-7hxq

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/08/GHSA-333g-rpr4-7hxq/GHSA-333g-rpr4-7hxq.json
Aliases
  • CVE-2019-15224
Published
2019-08-20T14:29:03Z
Modified
2023-03-18T05:55:37.159189Z
Details

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Users of an affected version should consider downgrading to the last non-affected version of 1.6.9, or upgrading to 1.7.x. Additionally, a set of other minor gems have been partially or completely yanked and are included in this advisory. These include cronparser, coinbase, blockchainwallet, awesome-bot, doge-coin, capistrano-colors, bitcoinvanity, litacoin, coming-soon, and omniauthamazon.

References

Affected packages

RubyGems / rest-client

rest-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.6.10
Fixed
1.7.0

Affected versions

1.*

1.6.14
1.7.0.rc1

Database specific

{
    "last_known_affected_version_range": "<= 1.6.13"
}

RubyGems / cron_parser

cron_parser

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.13

Affected versions

Database specific

{
    "last_known_affected_version_range": "<= 1.0.14"
}

RubyGems / cron_parser

cron_parser

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0.1.4

Affected versions

0.*

0.1.4

RubyGems / coin_base

coin_base

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

RubyGems / blockchain_wallet

blockchain_wallet

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

RubyGems / awesome-bot

awesome-bot

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

RubyGems / doge-coin

doge-coin

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

RubyGems / capistrano-colors

capistrano-colors

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

RubyGems / bitcoin_vanity

bitcoin_vanity

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

RubyGems / coming-soon

coming-soon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

RubyGems / omniauth_amazon

omniauth_amazon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions