CVE-2019-13354

Published
View on NVD ↗
CVSS v3
N/A
CVSS v2
7.5
HIGH
Affected
2
PROJECTS

Description

The strong_password gem 0.0.7 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 0.0.6.

Entropy-based password strength checking for Ruby and Rails.
GitHubGitHub
338
Entropy-based password strength checking for Ruby and ActiveModel
RubyGemsRubyGems
4.14M