Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38826
HistoryJan 11, 2023 - 2:35 a.m.

Information Disclosure

2023-01-1102:35:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7
pghero
information disclosure
vulnerability
error handling
sensitive information
home controller

EPSS

0.002

Percentile

58.8%

pghero is vulnerable to Information Disclosure. The vulnerability exists because the explain function in home_controller.rb does not properly handle sensitive information in the error message of query results, allowing an attacker to access sensitive information.

EPSS

0.002

Percentile

58.8%