CRITICAL9.8
GHSA-wg6j-r28m-7293
Code backdoor in simple_captcha2
Details
The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
Are you affected?
Enter the version of the package you're using.
Affected packages
RubyGems/simple_captcha2
No fixed version published yet for simple_captcha2 (bundler). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2019-14282[ADVISORY]
- https://github.com/rubygems/rubygems.org/issues/2073[WEB]
- https://github.com/pludoni/simple-captcha[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/simple_captcha2/CVE-2019-14282.yml[WEB]
- https://rubygems.org/gems/simple_captcha2/versions[WEB]
- https://security.snyk.io/vuln/SNYK-RUBY-SIMPLECAPTCHA2-455501[WEB]