CVE-2014-4993

Description

(1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place credentials on the openssl command line, which allows local users to obtain sensitive information by listing the process.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.064

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-4993 are affected in Ruby-backup-agoddard 3.0.28Windows
Vulnerabilities CVE-2014-4993 are affected in Ruby-backup_checksum 3.0.23Windows
Vulnerabilities CVE-2014-4993 are affected in Ruby-backup-agoddard for Linux 3.0.28Linux
Vulnerabilities CVE-2014-4993 are affected in Ruby-backup_checksum for Linux 3.0.23Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234