Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-15224

Опубликовано: 19 авг. 2019
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

The rest-client rubygem, hosted on rubygems.org, was compromised and released containing malware in versions 1.6.10 to 1.6.13. Applications using these versions of the rest-client rubygem should be considered compromised.

Отчет

OpenShift Container Platform is not vulnerable to this issue as it does not use the affected versions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5cfme-amazon-smartstateNot affected
CloudForms Management Engine 5cfme-gemsetNot affected
Red Hat OpenShift Container Platform 3.10rubygem-rest-clientNot affected
Red Hat OpenShift Container Platform 3.11rubygem-rest-clientNot affected
Red Hat OpenShift Container Platform 3.9rubygem-rest-clientNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-fluentdNot affected
Red Hat Satellite 6rubygem-rest-clientNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-348
https://bugzilla.redhat.com/show_bug.cgi?id=1743940rubygem-rest-client: code-execution backdoor insterted by third party

EPSS

Процентиль: 88%
0.0355
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 7 лет назад

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

CVSS3: 9.8
nvd
около 7 лет назад

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

CVSS3: 9.8
debian
около 7 лет назад

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on ...

CVSS3: 9.8
github
около 7 лет назад

rest-client Gem Contains Malicious Code

EPSS

Процентиль: 88%
0.0355
Низкий

9.8 Critical

CVSS3