PT-2018-4244 · Ruby · Lynx

Tetravista

·

Published

2018-01-10

·

Updated

2019-05-06

·

CVE-2014-5002

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions lynx gem versions prior to 1.0.0
Description The issue allows local users to obtain sensitive information by listing processes because the configured password is placed on command lines. As of version 1.0.0, the --password option is no longer supported, and passwords are only configured in a configuration file, preventing command line exposure.
Recommendations For versions prior to 1.0.0, update to version 1.0.0 or later, as it removes the --password option and configures passwords solely through a configuration file, thus mitigating the risk of password exposure on the command line.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-5002
GHSA-94CQ-7CCQ-CMCM

Affected Products

Lynx