PT-2018-4243 · Ruby · Kcapifony

Larry W. Cashdollar

+1

·

Published

2018-01-10

·

Updated

2018-07-23

·

CVE-2014-5001

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kcapifony gem version 2.1.6
Description The issue allows local users to obtain sensitive database user passwords by listing the processes, as the passwords are placed on the command lines of mysqldump, pg dump, mysql, and psql.
Recommendations For kcapifony gem version 2.1.6, consider restricting access to the process list to minimize the risk of exploitation. As a temporary workaround, avoid using the kcapifony gem until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-5001
GHSA-6FCQ-3CM2-J3J5

Affected Products

Kcapifony