Back

CRITICAL

rubygem-rest-client: code-execution backdoor insterted by third party

Published Aug 19, 2019

Description

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.

Affected products

Remediation

Red Hat statement

OpenShift Container Platform is not vulnerable to this issue as it does not use the affected versions.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 19, 2019
Updated Aug 5, 2024
Reserved Aug 19, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 19, 2019
GHSA-333G-RPR4-7HXQ