Lucene search

K
osvGoogleOSV:GHSA-W9VV-FVW8-J6Q3
HistoryMay 14, 2022 - 3:48 a.m.

codders-dataset Process Table Local Plaintext Credential Disclosure

2022-05-1403:48:04
Google
osv.dev
7

0.0004 Low

EPSS

Percentile

5.1%

lib/dataset/database/mysql.rb and lib/dataset/database/postgresql.rb in the codders-dataset gem 1.3.2.1 for Ruby both place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.

CPENameOperatorVersion
codders-dataseteq1.3.2.1

0.0004 Low

EPSS

Percentile

5.1%

Related for OSV:GHSA-W9VV-FVW8-J6Q3