diff --git a/advisories/github-reviewed/2019/07/GHSA-4g4c-8gqh-m4vm/GHSA-4g4c-8gqh-m4vm.json b/advisories/github-reviewed/2019/07/GHSA-4g4c-8gqh-m4vm/GHSA-4g4c-8gqh-m4vm.json index 9a0ff15ac91..026a4cf7b00 100644 --- a/advisories/github-reviewed/2019/07/GHSA-4g4c-8gqh-m4vm/GHSA-4g4c-8gqh-m4vm.json +++ b/advisories/github-reviewed/2019/07/GHSA-4g4c-8gqh-m4vm/GHSA-4g4c-8gqh-m4vm.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4g4c-8gqh-m4vm", - "modified": "2023-01-25T22:42:41Z", + "modified": "2023-08-29T14:11:16Z", "published": "2019-07-16T00:41:55Z", "aliases": [ "CVE-2019-13589" ], - "summary": "Inclusion of Functionality from Untrusted Control Sphere in paranoid2", + "summary": "paranoid2 gem Code backdoor", "details": "The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5.", "severity": [ { @@ -20,6 +20,11 @@ "ecosystem": "RubyGems", "name": "paranoid2" }, + "ecosystem_specific": { + "affected_functions": [ + "" + ] + }, "versions": [ "1.1.6" ] @@ -34,6 +39,14 @@ "type": "WEB", "url": "https://github.com/rubygems/rubygems.org/issues/2051" }, + { + "type": "PACKAGE", + "url": "https://github.com/anjlab/paranoid2" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/paranoid2/CVE-2019-13589.yml" + }, { "type": "WEB", "url": "https://rubygems.org/gems/paranoid2/versions"