The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Lynx |
Lynx_project |
* |
1.0.0 (excluding) |
References