Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vr22-43gj-rx3f

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

omniauth-weibo-oauth2 included a code-execution backdoor inserted by a third party

The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.

Пакеты

Наименование

omniauth-weibo-oauth2

rubygems
Затронутые версииВерсия исправления

>= 0.4.6, < 0.5.1

0.5.1

EPSS

Процентиль: 70%
0.00649
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.

EPSS

Процентиль: 70%
0.00649
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-94