CVE-2019-15224
CRITICALrest-client 1.6.10-1.6.13 - Remote Code Execution via Malicious Gem
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-15224. PoCs published by chef-cft.
AI-analyzed exploit summary This repository provides an InSpec-based scanner to detect the presence of malicious versions of the `rest-client` gem (CVE-2019-15224) and other related malicious gems on a filesystem. It uses system commands to search for directories matching specific patterns.
Description
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.
Exploits (1)
This repository provides an InSpec-based scanner to detect the presence of malicious versions of the `rest-client` gem (CVE-2019-15224) and other related malicious gems on a filesystem. It uses system commands to search for directories matching specific patterns.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H