Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q6cw-2553-7837

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

newrelic_rpm Gem Discloses Sensitive Information

Ruby agent 3.2.0 through 3.5.3.23 serializes sensitive data when communicating with servers operated by New Relic, which allows remote attackers to obtain sensitive information (database credentials and SQL statements) by sniffing the network and deserializing the data.

Пакеты

Наименование

newrelic_rpm

rubygems
Затронутые версииВерсия исправления

>= 3.2.0, <= 3.5.3.23

3.5.3.24

EPSS

Процентиль: 48%
0.0025
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
почти 13 лет назад

Ruby agent 3.2.0 through 3.5.2 serializes sensitive data when communicating with servers operated by New Relic, which allows remote attackers to obtain sensitive information (database credentials and SQL statements) by sniffing the network and deserializing the data.

EPSS

Процентиль: 48%
0.0025
Низкий

Дефекты

CWE-200