CRITICAL 9.8 RubyGems

Code backdoor in simple_captcha2

GHSA-wg6j-r28m-7293 · CVE-2019-14282

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.

Ready to move

Start Securing

Free, no credit card | First findings in minutes