GHSA-hhxm-4f85-rgr8

Suggest an improvement
Source
https://github.com/advisories/GHSA-hhxm-4f85-rgr8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-hhxm-4f85-rgr8/GHSA-hhxm-4f85-rgr8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hhxm-4f85-rgr8
Withdrawn
2020-06-16T21:40:22Z
Published
2019-02-05T16:25:34Z
Modified
2024-12-02T05:51:04Z
Summary
High severity vulnerability that affects many_versioned_gem
Details

Logs password in plaintext

Impact

Logs the password used in plaintext. The password should masked in logs to prevent it leaking.

Patches

Has the problem been patched? What versions should users upgrade to?

Workarounds

none

See also

Are there any links users can visit to find out more information?

Package Ecosystem

RubyGems

Package Name

many_versioned_gem

Affected Versions

< 0.2.2

Patches

0.2.3

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T21:40:22Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

RubyGems / many_versioned_gem

Package

Name
many_versioned_gem
Purl
pkg:gem/many_versioned_gem

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.2.3

Affected versions

0.*
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.1.0
0.1.1
0.1.2
0.1.3
0.2.0
0.2.1
0.2.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-hhxm-4f85-rgr8/GHSA-hhxm-4f85-rgr8.json"