test/tc_database.rb in the lean-ruport gem 0.3.8 for Ruby places the mysql user password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
Loading...
Loading...
Score 7.8 from GitHub Security Advisory (severity: HIGH) published 2022-05-14. NVD baseline CVSS 7.8; sources differ by 0.0.
test/tc_database.rb in the lean-ruport gem 0.3.8 for Ruby places the mysql user password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
January 10, 2018
November 21, 2024
See which npm, PyPI, Go, and Maven packages are affected by CVE-2014-4998
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.