CVE Vulnerabilities

CVE-2014-5002

Published: Jan 10, 2018 | Modified: May 06, 2019
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.

Affected Software

Name Vendor Start Version End Version
Lynx Lynx_project * 1.0.0 (excluding)

References