VDB
Sign up
CRITICAL9.8

GHSA-rqp5-pg7w-832p

datagrid contains code Injection backdoor

Details

The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/datagrid

No fixed version published yet for datagrid (bundler). Pin to a known-safe version or switch to an alternative.

References