Skip to content

Commit 8754e1a

Browse files
committed
Merge branch 'pr/409'
2 parents 7136074 + 7a69f6d commit 8754e1a

File tree

16 files changed

+280
-0
lines changed

16 files changed

+280
-0
lines changed

gems/awesome-bot/CVE-2019-15224.yml

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
gem: awesome-bot
3+
cve: 2019-15224
4+
ghsa: 333g-rpr4-7hxq
5+
url: https://github.com/rubygems/rubygems.org/issues/2097
6+
date: 2019-08-20
7+
title: Code execution backdoor in awesome-bot
8+
description: |
9+
The awesome-bot gem 1.18.0 for Ruby, as distributed on RubyGems.org, included a code-execution
10+
backdoor inserted by a third party.
11+
12+
Users of an affected version should consider downgrading to the last non-affected version of
13+
1.17.2 or upgrading to 1.19.x.
14+
unaffected_versions:
15+
- "< 1.18.0"
16+
- "> 1.18.0"
17+
related:
18+
url:
19+
- https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked#19-aug-2019
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
---
2+
gem: bitcoin_vanity
3+
cve: 2019-15224
4+
ghsa: 333g-rpr4-7hxq
5+
url: https://github.com/rubygems/rubygems.org/issues/2097
6+
date: 2019-08-20
7+
title: Code execution backdoor in bitcoin_vanity
8+
description: |
9+
The bitcoin_vanity gem 4.3.3 for Ruby, as distributed on RubyGems.org, included a code-execution
10+
backdoor inserted by a third party.
11+
12+
No unaffected version is known to exist, as the gem appears to have been entirely removed.
13+
unaffected_versions:
14+
- "< 4.3.3"
15+
- "> 4.3.3"
16+
related:
17+
url:
18+
- https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked#19-aug-2019
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
gem: blockchain_wallet
3+
cve: 2019-15224
4+
ghsa: 333g-rpr4-7hxq
5+
url: https://github.com/rubygems.org/issues/2097
6+
date: 2019-08-20
7+
title: Code execution backdoor in blockchain_wallet
8+
description: |
9+
The blockchain_wallet gem 0.0.6 through 0.0.7 for Ruby, as distributed on RubyGems.org, included
10+
a code-execution backdoor inserted by a third party.
11+
12+
Users of an affected version should consider downgrading to the last non-affected version of
13+
0.0.5.
14+
unaffected_versions:
15+
- "< 0.0.6"
16+
- "> 0.0.7"
17+
related:
18+
url:
19+
- https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked#19-aug-2019
Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
gem: capistrano-colors
3+
cve: 2019-15224
4+
ghsa: 333g-rpr4-7hxq
5+
url: https://github.com/rubygems.org/issues/2097
6+
date: 2019-08-20
7+
title: Code execution backdoor in capistrano-colors
8+
description: |
9+
The capistrano-colors 0.5.5 gem for Ruby, as distributed on RubyGems.org, included a
10+
code-execution backdoor inserted by a third party.
11+
12+
Users of an affected version should consider downgrading to the last non-affected version of
13+
0.5.4.
14+
unaffected_versions:
15+
- "< 0.5.5"
16+
- "> 0.5.5"
17+
related:
18+
url:
19+
- https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked#19-aug-2019

gems/coin_base/CVE-2019-15224.yml

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
---
2+
gem: coin_base
3+
cve: 2019-15224
4+
ghsa: 333g-rpr4-7hxq
5+
url: https://github.com/rubygems.org/issues/2097
6+
date: 2019-08-20
7+
title: Code execution backdoor in coin_base
8+
description: |
9+
The coin_base gem 4.2.1 through 4.2.2 for Ruby, as distributed on RubyGems.org, included a
10+
code-execution backdoor inserted by a third party.
11+
12+
No unaffected version is known to exist, as the gem appears to have been entirely removed.
13+
unaffected_versions:
14+
- "< 4.2.1"
15+
- "> 4.2.2"
16+
related:
17+
url:
18+
- https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked#19-aug-2019

gems/coming-soon/CVE-2019-15224.yml

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
---
2+
gem: coming-soon
3+
cve: 2019-15224
4+
ghsa: 333g-rpr4-7hxq
5+
url: https://github.com/rubygems.org/issues/2097
6+
date: 2019-08-20
7+
title: Code execution backdoor in coming-soon
8+
description: |
9+
The coming-soon gem 0.2.8 for Ruby, as distributed on RubyGems.org, included a code-execution
10+
backdoor inserted by a third party.
11+
12+
No unaffected version is known to exist, as the gem appears to have been entirely removed.
13+
unaffected_versions:
14+
- "< 0.2.8"
15+
- "> 0.2.8"
16+
related:
17+
url:
18+
- https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked#19-aug-2019

gems/cron_parser/CVE-2019-15224.yml

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
---
2+
gem: cron_parser
3+
cve: 2019-15224
4+
ghsa: 333g-rpr4-7hxq
5+
url: https://github.com/rubygems.org/issues/2097
6+
date: 2019-08-20
7+
title: Code execution backdoor in cron_parser
8+
description: |
9+
The cron_parser gem 0.1.4, 1.0.12, and 1.0.13 as distributed on RubyGems.org, included a
10+
code-execution backdoor inserted by a third party.
11+
12+
No unaffected version is known to exist, as the gem appears to have been entirely removed.
13+
unaffected_versions:
14+
- "< 1.0.12"
15+
- "> 1.0.13"
16+
- "< 0.1.4"
17+
- "> 0.1.4"
18+
related:
19+
url:
20+
- https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked#19-aug-2019

gems/datagrid/CVE-2019-14281.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
---
2+
gem: datagrid
3+
cve: 2019-14281
4+
ghsa: rqp5-pg7w-832p
5+
url: https://github.com/rubygems/rubygems.org/issues/2072
6+
date: 2019-07-31
7+
title: Code execution backdoor in datagrid
8+
description: |
9+
The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included
10+
a code-execution backdoor inserted by a third party.
11+
unaffected_versions:
12+
- "< 1.0.6"
13+
- "> 1.0.6"
14+
cvss_v3: 9.8

gems/doge-coin/CVE-2019-15224.yml

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,19 @@
1+
---
2+
gem: doge-coin
3+
cve: 2019-15224
4+
ghsa: 333g-rpr4-7hxq
5+
url: https://github.com/rubygems.org/issues/2097
6+
date: 2019-08-20
7+
title: Code execution backdoor in doge-coin
8+
description: |
9+
The doge-coin gem 1.0.2 for Ruby, as distributed on RubyGems.org, included a code-execution
10+
backdoor inserted by a third party.
11+
12+
Users of an affected version should consider downgrading to the last non-affected version of
13+
1.0.1.
14+
unaffected_versions:
15+
- "< 1.0.2"
16+
- "> 1.0.2"
17+
related:
18+
url:
19+
- https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked#19-aug-2019

gems/lita_coin/CVE-2019-15224.yml

Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
---
2+
gem: lita_coin
3+
cve: 2019-15224
4+
ghsa: 333g-rpr4-7hxq
5+
url: https://github.com/rubygems.org/issues/2097
6+
date: 2019-08-20
7+
title: Code execution backdoor in lita_coin
8+
description: |
9+
The lita_coin gem 0.0.3 for Ruby, as distributed on RubyGems.org, included a code-execution
10+
backdoor inserted by a third party.
11+
12+
No unaffected version is known to exist, as the gem appears to have been entirely removed.
13+
unaffected_versions:
14+
- "< 0.0.3"
15+
- "> 0.0.3"
16+
related:
17+
url:
18+
- https://github.com/rubygems/rubygems.org/wiki/Gems-yanked-and-accounts-locked#19-aug-2019

0 commit comments

Comments
 (0)