Code Execution Vulnerability in Omniauth-Weibo-OAuth2 Gem by Beenhero
CVE-2019-17268
9.8CRITICAL
Key Information:
- Status
- Vendor
- CVE Published:
- 7 February 2020
What is CVE-2019-17268?
The omniauth-weibo-oauth2 gem, as distributed on RubyGems.org, has been compromised by a third party, introducing a backdoor that enables code execution. The affected version 0.4.6 poses a significant risk to applications relying on this gem, while versions 0.4.5 and prior, along with 0.5.1 and later, remain secure. Users are advised to update to a safe version as soon as possible to mitigate potential security issues.
