Lucene search

K
osvGoogleOSV:GHSA-WXCW-RQXC-HJ85
HistoryMay 01, 2022 - 6:31 p.m.

FTP backend for Duplicity Discloses Passwords to Process Listing

2022-05-0118:31:03
Google
osv.dev
1

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

The FTP backend for Duplicity before 0.4.9 sends the password as a command line argument when calling ncftp, which might allow local users to read the password by listing the process and its arguments.

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%