Vulnerabilities (CVE)

Filtered by vendor Codders-dataset Project Subscribe
Filtered by product Codders-dataset
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-4991 1 Codders-dataset Project 1 Codders-dataset 2024-02-28 2.1 LOW 7.8 HIGH
(1) lib/dataset/database/mysql.rb and (2) lib/dataset/database/postgresql.rb in the codders-dataset gem 1.3.2.1 for Ruby place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.