{ "schema_version": "1.4.0", "id": "GHSA-4g4c-8gqh-m4vm", "modified": "2023-08-29T14:11:16Z", "published": "2019-07-16T00:41:55Z", "aliases": [ "CVE-2019-13589" ], "summary": "paranoid2 gem Code backdoor", "details": "The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [ { "package": { "ecosystem": "RubyGems", "name": "paranoid2" }, "versions": [ "1.1.6" ] } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-13589" }, { "type": "WEB", "url": "https://github.com/rubygems/rubygems.org/issues/2051" }, { "type": "PACKAGE", "url": "https://github.com/anjlab/paranoid2" }, { "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/paranoid2/CVE-2019-13589.yml" }, { "type": "WEB", "url": "https://rubygems.org/gems/paranoid2/versions" }, { "type": "WEB", "url": "https://snyk.io/vuln/SNYK-RUBY-PARANOID2-451600" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/109281" } ], "database_specific": { "cwe_ids": [ "CWE-829" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2019-07-15T23:22:39Z", "nvd_published_at": "2019-07-14T16:15:00Z" } }