CVE-2014-5000
EUVD-2018-016410.01.2018, 18:29
The login function in lib/lawn.rb in the lawn-login gem 0.0.7 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive information by listing the process.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lawn-login_project | lawn-login | 0.0.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References