9.8
CVSSv3

CVE-2019-17268

Published: 07/02/2020 Updated: 11/02/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions up to and including 0.4.5, and 0.5.1 and later, are unaffected.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

omniauth-weibo-oauth2 project omniauth-weibo-oauth2 0.4.6

Github Repositories

OmniAuth Oauth2 strategy for weibo.com.

Status OmniAuth Weibo OAuth2 Weibo OAuth2 Strategy for OmniAuth 10 Read Weibo OAuth2 docs for more details: openweibocom/wiki/授权机制 Security CVE-2019-17268 Issue #36 Installing Add to your Gemfile: gem 'omniauth-weibo-oauth2' Then bundle install Or install it yourself as: $ gem install omniauth-weibo-oa