Skip to content

Unauthorized gem takeover for some gems

Critical
chesterbr published GHSA-966m-q74f-gx4h Jul 27, 2022

Package

composer other package (Composer)

Affected versions

11

Patched versions

22
nuget some package (NuGet)
< 1.2.3
1.2.3.453
cargo 📦🌹 (Rust)
aa
bb

Description

Impact

Oh noes, you've been hacked!!

Patches

Update, update, update like you are an XBox that spent a summer in storage

Workarounds

Curl into a corner and cry; Update your linkedin profile

References

http://gunshowcomic.com/648

For more information

If you have any questions or comments about this advisory:

Severity

Critical

CVE ID

No known CVE

Weaknesses

No CWEs