Skip to main content

Vendor/product archive

rest-client_project / rest-client CVEs

Beta · best-effort

3 CVEs tagged to rest-client_project / rest-client2 Critical, 0 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2019-15224

Published Aug 19, 2019

The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-1820

Published Aug 9, 2017

REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of coo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-3448

Published Apr 29, 2015

REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1