MAL-2024-10221

See a problem?
Import Source
https://github.com/ossf/malicious-packages/blob/main/osv/malicious/rubygems/johnny_five/MAL-2024-10221.json
JSON Data
https://api.test.osv.dev/v1/vulns/MAL-2024-10221
Published
2024-10-16T15:03:54Z
Modified
2024-10-16T15:03:54Z
Summary
Malicious code in johnny_five (RubyGems)
Details

-= Per source details. Do not edit below this line.=-

Database specific
{
    "malicious-packages-origins": [
        {
            "modified_time": "2024-10-16T15:03:54Z",
            "import_time": "2024-10-24T00:57:12.951120271Z",
            "versions": [
                "0.8.0",
                "0.9.4",
                "1.0.0",
                "1.0.9",
                "1.1.0",
                "1.1.0.1",
                "1.1.1",
                "1.2.0",
                "1.2.1",
                "1.98.0",
                "1.99.0",
                "9.0.0",
                "9.1.0",
                "9.1.1"
            ],
            "id": "RLMA-2024-10277",
            "source": "reversing-labs",
            "sha256": "6ba9da2aa8f85947a7aa1ceca4552388a358ea653ab8e2a00e4b9672b3091aec"
        }
    ]
}
References
Credits

Affected packages

RubyGems / johnny_five

Package

Name
johnny_five
Purl
pkg:gem/johnny_five

Affected ranges

Affected versions

0.*

0.8.0
0.9.4

1.*

1.0.0
1.0.9
1.1.0
1.1.0.1
1.1.1
1.2.0
1.2.1
1.98.0
1.99.0

9.*

9.0.0
9.1.0
9.1.1