Local User Information Disclosure in Ruby's xaviershay-dm-rails Gem
CVE-2015-2179

Currently unrated

Key Information:

Vendor

Ruby

Vendor
CVE Published:
12 December 2023

What is CVE-2015-2179?

The xaviershay-dm-rails gem version 0.10.3.8 for Ruby has a vulnerability that allows local users to access sensitive MySQL credentials by listing processes and their arguments. This exposure could lead to unauthorized data access, making it crucial for users to evaluate their system's security and apply necessary patches.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.