Rubysec

Providing security resources for the Ruby community.
Follow us @rubysec or email us via info at rubysec.com

Advisory Archive

Back

---
gem: paranoid2
date: 2019-07-16
url: https://github.com/rubygems/rubygems.org/issues/2051
cve: 2019-13589
title: Code backdoor in paranoid2
description: |
  The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included
  a code-execution backdoor inserted by a third party.

  The current version, without this backdoor, is 1.1.5.
cvss_v3: '9.8'
unaffected_versions:
- "> 1.1.6"
- "< 1.1.6"