CRITICAL9.8
GHSA-4g4c-8gqh-m4vm
paranoid2 gem Code backdoor
Details
The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.
Are you affected?
Enter the version of the package you're using.
Affected packages
RubyGems/paranoid2
No fixed version published yet for paranoid2 (bundler). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-13589[ADVISORY]
- https://github.com/rubygems/rubygems.org/issues/2051[WEB]
- https://github.com/anjlab/paranoid2[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/paranoid2/CVE-2019-13589.yml[WEB]
- https://rubygems.org/gems/paranoid2/versions[WEB]
- https://snyk.io/vuln/SNYK-RUBY-PARANOID2-451600[WEB]
- http://www.securityfocus.com/bid/109281[WEB]