The login function in lib/lawn.rb in the lawn-login gem 0.0.7 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive information by listing the process.
Loading...
Loading...
Score 7.8 from GitHub Security Advisory (severity: HIGH) published 2018-01-22. NVD baseline CVSS 7.8; sources differ by 0.0.
The login function in lib/lawn.rb in the lawn-login gem 0.0.7 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive information by listing the process.
January 10, 2018
November 21, 2024
See which npm, PyPI, Go, and Maven packages are affected by CVE-2014-5000
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.