Описание
xaviershay-dm-rails Gem for Ruby exposes sensitive information via the process table
xaviershay-dm-rails Gem for Ruby contains a flaw in the execute() function in /datamapper/dm-rails/blob/master/lib/dm-rails/storage.rb. The issue is due to the function exposing sensitive information via the process table. This may allow a local attack to gain access to MySQL credential information.
Пакеты
Наименование
xaviershay-dm-rails
rubygems
Затронутые версииВерсия исправления
<= 1.2.0
Отсутствует
Связанные уязвимости
CVSS3: 5.5
nvd
около 2 лет назад
The xaviershay-dm-rails gem 0.10.3.8 for Ruby allows local users to discover MySQL credentials by listing a process and its arguments.