CVE-2014-5004

Description

lib/brbackup.rb in the brbackup gem 0.1.1 for Ruby places the database password on the mysql command line, which allows local users to obtain sensitive information by listing the process.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.076

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2014-5004 are affected in Ruby-brbackup 0.1.1Windows
Vulnerabilities CVE-2014-5004 are affected in Ruby-brbackup for Linux 0.1.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234