CVE-2014-5000
10.01.2018, 18:29
The login function in lib/lawn.rb in the lawn-login gem 0.0.7 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive information by listing the process.Enginsight
Vendor | Product | Version |
---|---|---|
lawn-login_project | lawn-login | 0.0.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References