Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk0Y3EtN2NjcS1jbWNt

lynx doesn't properly sanitize user input and exposes database password to unauthorized users

The lynx gem prior to 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.

As of version 1.0.0, lynx no longer supports a --password option. Passwords are only configured in a configuration file, so it's no longer possible to expose passwords on the command line.

Permalink: https://github.com/advisories/GHSA-94cq-7ccq-cmcm
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk0Y3EtN2NjcS1jbWNt
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: about 6 years ago
Updated: 8 months ago


CVSS Score: 7.8
CVSS vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Identifiers: GHSA-94cq-7ccq-cmcm, CVE-2014-5002
References: Repository: https://github.com/panthomakos/lynx
Blast Radius: 13.3

Affected Packages

rubygems:lynx
Dependent packages: 0
Dependent repositories: 51
Downloads: 54,617 total
Affected Version Ranges: <= 0.4.0
Fixed in: 1.0.0
All affected versions: 0.0.1, 0.0.2, 0.1.0, 0.2.0, 0.2.1, 0.3.0, 0.4.0
All unaffected versions: 1.0.0, 1.1.0, 1.1.1