9.8

CVE-2019-13589

Exploit
The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AnjlabParanoid2 Version1.1.6 SwPlatformruby
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.35% 0.9
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-829 Inclusion of Functionality from Untrusted Control Sphere

The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

http://www.securityfocus.com/bid/109281
Third Party Advisory
VDB Entry
https://github.com/rubygems/rubygems.org/issues/2051
Third Party Advisory
Exploit
Issue Tracking
https://rubygems.org/gems/paranoid2/versions
Vendor Advisory
https://snyk.io/vuln/SNYK-RUBY-PARANOID2-451600
Third Party Advisory