GHSA-q6cw-2553-7837

Suggest an improvement
Source
https://github.com/advisories/GHSA-q6cw-2553-7837
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-q6cw-2553-7837/GHSA-q6cw-2553-7837.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q6cw-2553-7837
Aliases
  • CVE-2013-0284
Published
2017-10-24T18:33:37Z
Modified
2024-12-05T05:39:23Z
Summary
newrelic_rpm Gem Discloses Sensitive Information
Details

Ruby agent 3.2.0 through 3.5.3.23 serializes sensitive data when communicating with servers operated by New Relic, which allows remote attackers to obtain sensitive information (database credentials and SQL statements) by sniffing the network and deserializing the data.

Database specific
{
    "cwe_ids":  [
        "CWE-200"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T21:51:15Z",
    "nvd_published_at":  "2013-04-09T20:55:01Z",
    "severity":  "MODERATE"
}
References

Affected packages

RubyGems / newrelic_rpm

Package

Name
newrelic_rpm
Purl
pkg:gem/newrelic_rpm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.0
Fixed
3.5.3.24

Affected versions

3.*
3.2.0
3.2.0.1
3.3.0.beta1
3.3.0
3.3.1.beta1
3.3.1.beta2
3.3.1
3.3.2.beta1
3.3.2.beta2
3.3.2
3.3.2.1
3.3.3.beta1
3.3.3.beta2
3.3.3
3.3.4.beta1
3.3.4
3.3.4.1
3.3.5.beta1
3.3.5
3.4.0.beta1
3.4.0.beta2
3.4.0
3.4.0.1
3.4.1.beta1
3.4.1
3.4.2.beta1
3.4.2
3.4.2.1
3.5.0
3.5.0.1
3.5.1.alpha
3.5.1.beta1
3.5.1.14.beta
3.5.1.14
3.5.2.17

Database specific

last_known_affected_version_range
"<= 3.5.3.23"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-q6cw-2553-7837/GHSA-q6cw-2553-7837.json"