PT-2023-10312 · Oracle · Mysql Server

·

CVE-2015-2179

·

Published

2023-01-26

·

Updated

2023-12-14

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions xaviershay-dm-rails gem version 0.10.3.8
Description The issue allows local users to discover MySQL credentials by listing a process and its arguments. This is due to a flaw in the execute() function in the /datamapper/dm-rails/blob/master/lib/dm-rails/storage.rb file, which exposes sensitive information via the process table. A local attack may gain access to MySQL credential information.
Recommendations For xaviershay-dm-rails gem version 0.10.3.8, consider disabling the execute() function in the /datamapper/dm-rails/blob/master/lib/dm-rails/storage.rb file as a temporary workaround until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-2179
GHSA-88P8-4VV5-82J7

Affected Products

Mysql Server