Lucene search

K
osvGoogleOSV:GHSA-5H5R-FFC4-C455
HistoryJul 08, 2019 - 8:32 p.m.

strong_password Ruby gem malicious version causing Remote Code Execution vulnerability

2019-07-0820:32:35
Google
osv.dev
6

EPSS

0.009

Percentile

82.9%

The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Version 0.0.8 does not contain the backdoor.

EPSS

0.009

Percentile

82.9%

Related for OSV:GHSA-5H5R-FFC4-C455