Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-94cq-7ccq-cmcm

Опубликовано: 24 янв. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

lynx doesn't properly sanitize user input and exposes database password to unauthorized users

The lynx gem prior to 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.

As of version 1.0.0, lynx no longer supports a --password option. Passwords are only configured in a configuration file, so it's no longer possible to expose passwords on the command line.

Пакеты

Наименование

lynx

rubygems
Затронутые версииВерсия исправления

<= 0.4.0

1.0.0

EPSS

Процентиль: 23%
0.00078
Низкий

7.8 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.8
nvd
около 8 лет назад

The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.

EPSS

Процентиль: 23%
0.00078
Низкий

7.8 High

CVSS3

Дефекты

CWE-200