lawn-login Gem for Ruby /lib/lawn.rb Process Table Local Plaintext Password Disclosure
Published: June 30, 2014
SECURITY IDENTIFIERS
- CVE: CVE-2014-5000 (NVD)
- GHSA: GHSA-rhgq-vv9x-j4p5
- OSVDB: OSVDB-108576
GEM
SEVERITY
CVSS v3.x: 7.8 (High)
PATCHED VERSIONS
None available.
DESCRIPTION
lawn-login Gem for Ruby contains a flaw in /lib/lawn.rb that is due to the application exposing password information in plaintext in the process table. This may allow a local attacker to gain access to password information.
