Rubysec

Providing security resources for the Ruby community.
Follow us @rubysec or email us via info at rubysec.com

Advisory Archive

Back

---
gem: simple_captcha2
date: 2019-07-31
url: https://github.com/rubygems/rubygems.org/issues/2073
cve: 2019-14282
title: Code backdoor in simple_captcha2
description: |
  The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org,
  included a code-execution backdoor inserted by a third party.
cvss_v3: '9.8'
unaffected_versions:
- "< 0.2.3"
- "> 0.2.3"