lib/brbackup.rb in the brbackup gem 0.1.1 for Ruby places the database password on the mysql command line, which allows local users to obtain sensitive information by listing the process.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-01-10T18:00:00

Updated: 2024-08-06T11:34:37.481Z

Reserved: 2014-07-17T00:00:00

Link: CVE-2014-5004

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-01-10T18:29:00.883

Modified: 2024-11-21T02:11:15.673

Link: CVE-2014-5004

cve-icon Redhat

No data.