{"id":"GHSA-q2hm-gx3f-h63q","summary":"Backdoor / Malicious code","details":"lita-coin 0.0.3 contains a backdoor mechanism that allows launching of hidden cryptocurrency mining operations inside the project. The code also contained a backdoor mechanism that allowed the attacker to send a cookie file back to a compromised project, and allow the attacker to execute malicious commands.","modified":"2021-02-23T21:23:16Z","published":"2021-02-23T21:23:16Z","withdrawn":"2021-02-23T21:23:16Z","database_specific":{"cwe_ids":[],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2019-08-28T16:16:58Z","nvd_published_at":null},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15224"},{"type":"WEB","url":"https://www.zdnet.com/article/backdoor-code-found-in-11-ruby-libraries"}],"affected":[{"package":{"name":"lita-coin","ecosystem":"RubyGems","purl":"pkg:gem/lita-coin"},"versions":["0.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-q2hm-gx3f-h63q/GHSA-q2hm-gx3f-h63q.json"}}],"schema_version":"1.9.0"}