{"id":"GHSA-wg6j-r28m-7293","summary":"Code backdoor in simple_captcha2","details":"The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.","aliases":["CVE-2019-14282"],"modified":"2026-03-13T21:57:02.838993Z","published":"2019-07-31T04:21:19Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2019-07-31T04:00:04Z","nvd_published_at":"2019-07-26T05:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14282"},{"type":"WEB","url":"https://github.com/rubygems/rubygems.org/issues/2073"},{"type":"PACKAGE","url":"https://github.com/pludoni/simple-captcha"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/simple_captcha2/CVE-2019-14282.yml"},{"type":"WEB","url":"https://rubygems.org/gems/simple_captcha2/versions"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-RUBY-SIMPLECAPTCHA2-455501"}],"affected":[{"package":{"name":"simple_captcha2","ecosystem":"RubyGems","purl":"pkg:gem/simple_captcha2"},"versions":["0.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/07/GHSA-wg6j-r28m-7293/GHSA-wg6j-r28m-7293.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}