PT-2018-4244 · Ruby · Lynx
Tetravista
·
Published
2018-01-10
·
Updated
2019-05-06
·
CVE-2014-5002
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
lynx gem versions prior to 1.0.0
Description
The issue allows local users to obtain sensitive information by listing processes because the configured password is placed on command lines. As of version 1.0.0, the
--password option is no longer supported, and passwords are only configured in a configuration file, preventing command line exposure.Recommendations
For versions prior to 1.0.0, update to version 1.0.0 or later, as it removes the
--password option and configures passwords solely through a configuration file, thus mitigating the risk of password exposure on the command line.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lynx