CVE-2019-17268: Omniauth-Weibo-OAUTH2 Project Omniauth-Weibo-OAUTH2
Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.
The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.
Affected products
- Omniauth-Weibo-OAUTH2 Project Omniauth-Weibo-OAUTH2: version 0.4.6 only
Published 2020-02-07. Last modified 2026-06-17.