(1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place credentials on the openssl command line, which allows local users to obtain sensitive information by listing the process.
{
"cwe_ids": [
"CWE-200"
],
"severity": "HIGH",
"nvd_published_at": "2018-01-10T18:29:00Z",
"github_reviewed": true,
"github_reviewed_at": "2023-01-23T14:10:09Z"
}