Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3448

Опубликовано: 12 янв. 2015
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.

Меры по смягчению последствий

The permissions on log files can be changed, e.g. using "chmod o-rwx" to prevent anyone but the user and group owner of the file from reading it. Additionally the group permissions can also be removed, e.g. "chmod g-rwx" if only the user owning the file should be able to see it.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenStack Foremanruby193-rubygem-rest-clientAffected
OpenStack Foremanrubygem-rest-clientAffected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installerruby193-rubygem-rest-clientAffected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installerrubygem-rest-clientAffected
Red Hat Enterprise MRG 2rubygem-rest-clientAffected
Red Hat OpenShift Enterprise 2ruby193-rubygem-rest-clientAffected
Red Hat Subscription Asset Managerruby193-rubygem-rest-clientAffected
Red Hat Subscription Asset Managerrubygem-rest-clientAffected
CloudForms Management Engine 5.4cfmeFixedRHBA-2015:110016.06.2015
CloudForms Management Engine 5.4cfme-gemsetFixedRHBA-2015:110016.06.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1240982rubygem-rest-client: unsanitized application logging

EPSS

Процентиль: 21%
0.00065
Низкий

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.

nvd
почти 11 лет назад

REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.

debian
почти 11 лет назад

REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and ...

github
больше 8 лет назад

rest-client allows local users to obtain sensitive information by reading the log

EPSS

Процентиль: 21%
0.00065
Низкий

2.1 Low

CVSS2