Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26163
HistoryAug 06, 2020 - 9:34 p.m.

Information Disclosure

2020-08-0621:34:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.006 Low

EPSS

Percentile

79.5%

ruby is vulnerable to information disclosure. The vulnerability exists in BasicSocket#read_nonblock(requested_size, buffer, exception: false) resizing the buffer to fit the requested size, but no data is copied which allows an attacker to access sensitive data from the interpreter.