MAL-2024-6413

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/active-model_serializers-jsonapi_embedded_records_deserializer/MAL-2024-6413.json
JSON Data
https://api.osv.dev/v1/vulns/MAL-2024-6413
Published
2024-06-25T13:46:18Z
Modified
2024-10-24T01:02:00Z
Summary
Malicious code in active-model_serializers-jsonapi_embedded_records_deserializer (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "sha256": "752ca25b40f2c9e4586f3904fd708d2188d4700ffecbcd39baf028e928c819bf",
            "import_time": "2024-06-28T02:51:34.761573341Z",
            "versions": [
                "0.1.1"
            ],
            "id": "RLMA-2024-05220",
            "source": "reversing-labs",
            "modified_time": "2024-06-25T13:46:18Z"
        },
        {
            "sha256": "42d626e35db30b528db6b215a621b992b92a4b5333b8fb80f3b97cf4022889c1",
            "import_time": "2024-10-24T01:00:40.024466075Z",
            "id": "RLUA-2024-09739",
            "source": "reversing-labs",
            "modified_time": "2024-10-16T14:56:49Z"
        }
    ]
}
References
Credits

Affected packages

RubyGems / active-model_serializers-jsonapi_embedded_records_deserializer

Package

Name
active-model_serializers-jsonapi_embedded_records_deserializer
Purl
pkg:gem/active-model_serializers-jsonapi_embedded_records_deserializer

Affected ranges

Affected versions

0.*

0.1.1