RubySec

Providing security resources for the Ruby community

CVE-2014-1835 (echor): echor Gem for Ruby Process Listing Local Plaintext Credential Disclosure

ADVISORIES

GEM

echor

SEVERITY

CVSS v3.x: 7.8 (High)

PATCHED VERSIONS

None.

DESCRIPTION

echor Gem for Ruby contains a flaw that is due to the program exposing credential information in the system process listing. This may allow a local attacker to gain access to plaintext credential information.