Rest Client Project maintains a narrowly scoped HTTP client testing and development tool that is embedded in development and QA environments, where its modest vulnerability footprint reflects the constraints of a single-product utility. The observed weaknesses affecting this product center on input-handling and communication-layer issues characteristic of client-side networking libraries. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rest Client Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15224CRITICAL The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are | Aug 19, 2019 | 9.8 | 33 | NO | NO |
CVE-2015-1820CRITICAL REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie information by leveraging passage of cook | Aug 9, 2017 | 9.8 | 25 | NO | NO |
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log. | Apr 29, 2015 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rest Client Project.
Media articles that mention a CVE ID that affects a product developed by Rest Client Project — matched by CVE ID, not by vendor name.