CVE-2014-4993
(1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place credentials on the openssl command line, which allows local users to obtain sensitive information by…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.51%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
(1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place credentials on the openssl command line, which allows local users to obtain sensitive information by listing the process.
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- backup-agoddard project/backup-agoddard · backup checksum project/backup checksum
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2014/07/07/11Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/07/07/12Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/07/17/5Mailing List, Third Party Advisory
- http://www.vapid.dhs.org/advisories/backup-agoddard-3.0.28.htmlExploit, Third Party Advisory
- http://www.vapid.dhs.org/advisories/backup_checksum-3.0.23.htmlExploit, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/07/07/11Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/07/07/12Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/07/17/5Mailing List, Third Party Advisory
- http://www.vapid.dhs.org/advisories/backup-agoddard-3.0.28.htmlExploit, Third Party Advisory
- http://www.vapid.dhs.org/advisories/backup_checksum-3.0.23.htmlExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.