xaviershay-dm-rails Gem for Ruby exposes sensitive information via the process table
Moderate severity
GitHub Reviewed
Published
Jan 26, 2023
to the GitHub Advisory Database
•
Updated Dec 14, 2023
Description
Published to the GitHub Advisory Database
Jan 26, 2023
Reviewed
Jan 26, 2023
Published by the National Vulnerability Database
Dec 12, 2023
Last updated
Dec 14, 2023
xaviershay-dm-rails Gem for Ruby contains a flaw in the
execute()
function in/datamapper/dm-rails/blob/master/lib/dm-rails/storage.rb
. The issue is due to the function exposing sensitive information via the process table. This may allow a local attack to gain access to MySQL credential information.References