Rubysec

Providing security resources for the Ruby community.
Follow us @rubysec or email us via info at rubysec.com

Advisory Archive

Back

---
gem: datagrid
date: 2019-07-31
url: https://github.com/rubygems/rubygems.org/issues/2072
cve: 2019-14281
title: Code execution backdoor in datagrid
description: |
  The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included
  a code-execution backdoor inserted by a third party.
cvss_v3: '9.8'
unaffected_versions:
- "< 1.0.6"
- "> 1.0.6"