RubySec

Providing security resources for the Ruby community

CVE-2013-7111 (bio-basespace-sdk): Bio Basespace SDK Gem for Ruby Command Line API Key Disclosure

ADVISORIES

GEM

bio-basespace-sdk

PATCHED VERSIONS

None.

DESCRIPTION

Bio Basespace SDK Gem for Ruby contains a flaw that is due to the API client code passing the API_KEY to a curl command. This may allow a local attacker to gain access to API key information by monitoring the process table.