GHSA-86cf-g34f-7462

Suggest an improvement
Source
https://github.com/advisories/GHSA-86cf-g34f-7462
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-86cf-g34f-7462/GHSA-86cf-g34f-7462.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-86cf-g34f-7462
Aliases
  • CVE-2014-4995
Published
2022-05-14T03:48:04Z
Modified
2023-11-08T03:57:42.653125Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
VladTheEnterprising allows local users to obtain sensitive information by reading MySQL root password from temporary file
Details

Race condition in lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to obtain sensitive information by reading the MySQL root password from a temporary file before it is removed.

References

Affected packages

RubyGems / VladTheEnterprising

Package

Name
VladTheEnterprising
Purl
pkg:gem/VladTheEnterprising

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.2

Affected versions

0.*

0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.2