Lucene search

K
freebsdFreeBSDFFE2D86C-07D9-11E5-9A28-001E67150279
HistoryJan 12, 2015 - 12:00 a.m.

rest-client -- plaintext password disclosure

2015-01-1200:00:00
vuxml.freebsd.org
22

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%

The open sourced vulnerability database reports:

REST Client for Ruby contains a flaw that is due to the application
logging password information in plaintext. This may allow a local
attacker to gain access to password information.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchrubygem-rest-client< 1.6.7_1UNKNOWN

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

EPSS

0

Percentile

5.1%