CVE-2019-13589
CRITICAL9.8EPSS 6.1%paranoid2 gem Code backdoor
Published: 7/16/2019Modified: 3/13/2026
Description
The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.
Affected packages (1)
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References (7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2019-13589
- PATCHhttps://github.com/anjlab/paranoid2
- WEBhttps://github.com/rubygems/rubygems.org/issues/2051
- WEBhttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/paranoid2/CVE-2019-13589.yml
- WEBhttps://rubygems.org/gems/paranoid2/versions
- WEBhttps://snyk.io/vuln/SNYK-RUBY-PARANOID2-451600
- WEBhttp://www.securityfocus.com/bid/109281