Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j55-pcw5-x4h2

Опубликовано: 13 авг. 2018
Источник: github
Github: Прошло ревью

Описание

active-support impersonates 'activesupport' gem

The active-support ruby gem gem is malware and duplicates the official activesupport (no hyphen) gem, but adds a compiled extension. The extension attempts to resolve a base64 encoded domain (29faea63.planfhntage.de), downloads a payload, and executes.

This trojan horse gem could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system. No version of this gem should be considered safe.

Пакеты

Наименование

active-support

rubygems
Затронутые версииВерсия исправления

Отсутствует

EPSS

Процентиль: 90%
0.05122
Низкий

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system.

CVSS3: 9.8
nvd
больше 7 лет назад

active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system.

CVSS3: 9.6
fstec
больше 7 лет назад

Уязвимость пакета active-support gem для языка программирования Ruby, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 90%
0.05122
Низкий

Дефекты

CWE-77