Bio Basespace SDK Gem for Ruby Command Line API Key Disclosure
Published: December 14, 2013
SECURITY IDENTIFIERS
- CVE: CVE-2013-7111 (NVD)
- GHSA: GHSA-xwr3-fmgj-mmfr
- OSVDB: OSVDB-101031
GEM
PATCHED VERSIONS
None available.
DESCRIPTION
Bio Basespace SDK Gem for Ruby contains a flaw that is due to the API client code passing the API_KEY to a curl command. This may allow a local attacker to gain access to API key information by monitoring the process table.
