Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

CVE-2019-17268 report for omniauth-weibo-oauth2 #36

Closed
mensfeld opened this issue Oct 9, 2019 · 4 comments
Closed

CVE-2019-17268 report for omniauth-weibo-oauth2 #36

mensfeld opened this issue Oct 9, 2019 · 4 comments

Comments

@mensfeld
Copy link

mensfeld commented Oct 9, 2019

Hey,

I took courtesy of reporting the malicious code injection in 0.4.6 into the CVE database.

https://diff.coditsu.io/gems/omniauth-weibo-oauth2/0.4.3/0.4.6

Just wanted to let you know. They initially assigned the CVE-2019-17268.

@NeverMin
Copy link
Collaborator

NeverMin commented Oct 9, 2019 via email

@mensfeld
Copy link
Author

ref: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17268

I believe that info about this breach should be more exposed.

@NeverMin
Copy link
Collaborator

NeverMin commented Oct 14, 2019

Hi @mensfeld ,

Thank you for your information, get a CVE number make me feel surprised, I sent the abuse report to ISP for now. more information see the Issue report please:

EDITED:
Server OFFLINE at 21:31 CST

update the report:
CVE-2019-17268-report

@mensfeld
Copy link
Author

Thank you! I did id so tools like bundler-audit can catch it.

Too many people use automatic dependencies upgrade tools, that's why I'm super paranoic about stuff like this.

I will close this issue as now it's on the Mitre side to verify.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants