CVE-2019-15224

unknown
Published 2019-08-20 ยท Modified 2024-02-16
CVSS v3
โ€”
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
โ€”

Description

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

Predictions

Exploit likelihood
30%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 0
sid Fixed 0
forky Fixed 0
bullseye Fixed 0
bookworm Fixed 0

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsblockchain_wallet!< 0.0.6,!> 0.0.7
ruby RubyGemsbitcoin_vanity!< 4.3.3,!> 4.3.3
ruby RubyGemsawesome-bot!< 1.18.0,!> 1.18.0
ruby RubyGemsdoge-coin!< 1.0.2,!> 1.0.2
ruby RubyGemscron_parser!< 1.0.12,!> 1.0.13,!< 0.1.4,!> 0.1.4
ruby RubyGemscoin_base!< 4.2.1,!> 4.2.2
ruby RubyGemscoming-soon!< 0.2.8,!> 0.2.8
ruby RubyGemscapistrano-colors!< 0.5.5,!> 0.5.5
ruby RubyGemsomniauth_amazon!< 1.0.1,!> 1.0.1
ruby RubyGemslita_coin!< 0.0.3,!> 0.0.3
ruby RubyGemsrest-client!<= 1.6.9,!>= 1.6.14
ruby RubyGemsrest-client>=1.6.10,<1.7.01.7.0
ruby RubyGemscron_parser>=1.0.13,<=1.0.14
ruby RubyGemscron_parser
ruby RubyGemscoin_base
ruby RubyGemsblockchain_wallet
ruby RubyGemsawesome-bot
ruby RubyGemsdoge-coin
ruby RubyGemscapistrano-colors
ruby RubyGemsbitcoin_vanity
ruby RubyGemscoming-soon
ruby RubyGemsomniauth_amazon

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.