Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRnNGMtOGdxaC1tNHZt

paranoid2 gem Code backdoor

The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.

Permalink: https://github.com/advisories/GHSA-4g4c-8gqh-m4vm
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRnNGMtOGdxaC1tNHZt
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: almost 5 years ago
Updated: 8 months ago


CVSS Score: 9.8
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-4g4c-8gqh-m4vm, CVE-2019-13589
References: Repository: https://github.com/rubygems/rubygems.org
Blast Radius: 16.9

Affected Packages

rubygems:paranoid2
Dependent packages: 0
Dependent repositories: 53
Downloads: 153,339 total
Affected Version Ranges: = 1.1.6
No known fixed version
All affected versions: