PT-2018-4244 · Ruby · Lynx

Tetravista

·

Publicado

2018-01-10

·

Atualizado

2019-05-06

·

CVE-2014-5002

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions lynx gem versions prior to 1.0.0
Description The issue allows local users to obtain sensitive information by listing processes because the configured password is placed on command lines. As of version 1.0.0, the --password option is no longer supported, and passwords are only configured in a configuration file, preventing command line exposure.
Recommendations For versions prior to 1.0.0, update to version 1.0.0 or later, as it removes the --password option and configures passwords solely through a configuration file, thus mitigating the risk of password exposure on the command line.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-5002
GHSA-94CQ-7CCQ-CMCM

Produtos afetados

Lynx