---
gem: paranoid2
cve: 2019-13589
ghsa: 4g4c-8gqh-m4vm
url: https://github.com/rubygems/rubygems.org/issues/2051
date: 2019-07-16
title: Code backdoor in paranoid2
description: |
  The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included
  a code-execution backdoor inserted by a third party.

  The current version, without this backdoor, is 1.1.5.
cvss_v3: 9.8
unaffected_versions:
  - "> 1.1.6"
  - "< 1.1.6"