Home / Companies / Snyk / Blog / Post Details
Content Deep Dive

Concerns of supply-chain attacks amplify as remote code execution was found in Ruby gem strong_password

Blog post from Snyk

Post Details
Company
Date Published
Author
Liran Tal
Word Count
615
Company Posts That Month
9
Language
English
Hacker News Points
4
Post removed?
No
Summary

The strong_password Ruby gem has been found to have a remote code execution vulnerability, CVE-2019-13354, which allows attackers to publish malicious versions of the gem and compromise account access rights. The vulnerable version was published on Rubygems.org six months after the last release with no source code changes. An attacker exploited this by publishing a malicious 0.0.7 version that triggers when an application is running in production, fetching further payload from pastebin.com to evaluate it, allowing remote command execution and providing the URL of the running application. The Ruby gems community quickly responded and removed the malicious version and assigned a CVE. This incident highlights the risks of supply-chain attacks and the importance of monitoring dependencies and taking swift action when vulnerabilities are discovered.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.