Описание
(1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place credentials on the openssl command line, which allows local users to obtain sensitive information by listing the process.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:backup-agoddard_project:backup-agoddard:3.0.28:*:*:*:*:ruby:*:*
cpe:2.3:a:backup_checksum_project:backup_checksum:3.0.23:*:*:*:*:ruby:*:*
EPSS
Процентиль: 20%
0.00064
Низкий
7.8 High
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
backup-agoddard and backup_checksum have Information Exposure vulnerability
EPSS
Процентиль: 20%
0.00064
Низкий
7.8 High
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-200