{"id":"GHSA-6fcq-3cm2-j3j5","summary":"Kcapifony gem for Ruby places database user passwords on the command line","details":"`lib/ksymfony1.rb` in the kcapifony gem 2.1.6 for Ruby places database user passwords on the (1) `mysqldump`, (2) `pg_dump`, (3) `mysql`, and (4) `psql` command lines, which allows local users to obtain sensitive information by listing the processes.","aliases":["CVE-2014-5001"],"modified":"2024-02-16T08:08:18.908198Z","published":"2018-07-23T19:50:11Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:19:03Z","nvd_published_at":"2018-01-10T18:29:00Z","cwe_ids":["CWE-200"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-5001"},{"type":"PACKAGE","url":"https://github.com/Kunstmaan/kCapifony"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/kcapifony/CVE-2014-5001.yml"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/07/07/21"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/07/17/5"},{"type":"WEB","url":"http://www.vapid.dhs.org/advisories/kcapifony-2.1.6.html"}],"affected":[{"package":{"name":"kcapifony","ecosystem":"RubyGems","purl":"pkg:gem/kcapifony"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.1.6"}]}],"versions":["2.1.3","2.1.4","2.1.5","2.1.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-6fcq-3cm2-j3j5/GHSA-6fcq-3cm2-j3j5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}