Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-15224

Опубликовано: 19 авг. 2019
Источник: redhat
CVSS3: 9.8

Описание

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

The rest-client rubygem, hosted on rubygems.org, was compromised and released containing malware in versions 1.6.10 to 1.6.13. Applications using these versions of the rest-client rubygem should be considered compromised.

Отчет

OpenShift Container Platform is not vulnerable to this issue as it does not use the affected versions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5cfme-amazon-smartstateNot affected
CloudForms Management Engine 5cfme-gemsetNot affected
Red Hat OpenShift Container Platform 3.10rubygem-rest-clientNot affected
Red Hat OpenShift Container Platform 3.11rubygem-rest-clientNot affected
Red Hat OpenShift Container Platform 3.9rubygem-rest-clientNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-fluentdNot affected
Red Hat Satellite 6rubygem-rest-clientNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-348
https://bugzilla.redhat.com/show_bug.cgi?id=1743940rubygem-rest-client: code-execution backdoor insterted by third party

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

CVSS3: 9.8
nvd
больше 6 лет назад

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

CVSS3: 9.8
debian
больше 6 лет назад

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on ...

CVSS3: 9.8
github
больше 6 лет назад

rest-client Gem Contains Malicious Code

9.8 Critical

CVSS3