xaviershay-dm-rails Gem for Ruby contains a flaw in the execute()
function in /datamapper/dm-rails/blob/master/lib/dm-rails/storage.rb
. The issue is due to the function exposing sensitive information via the process table. This may allow a local attack to gain access to MySQL credential information.
{ "nvd_published_at": "2023-12-12T17:15:07Z", "cwe_ids": [ "CWE-200" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-01-26T23:51:40Z" }