rest-client Gem Contains Malicious Code
Critical severity
GitHub Reviewed
Published
Aug 20, 2019
to the GitHub Advisory Database
•
Updated Aug 28, 2023
Description
Published by the National Vulnerability Database
Aug 19, 2019
Reviewed
Aug 20, 2019
Published to the GitHub Advisory Database
Aug 20, 2019
Last updated
Aug 28, 2023
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
Users of an affected version should consider downgrading to the last non-affected version of 1.6.9, or upgrading to 1.7.x.
Additionally, a set of other minor gems have been partially or completely yanked and are included in this advisory.
These include cron_parser, coin_base, blockchain_wallet, awesome-bot, doge-coin, capistrano-colors, bitcoin_vanity, lita_coin, coming-soon, and omniauth_amazon.
References