{"id":"CVE-2015-2179","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-2179","summary":"xaviershay-dm-rails Gem for Ruby exposes sensitive information via the process table","details":"xaviershay-dm-rails Gem for Ruby contains a flaw in the `execute()` function in `/datamapper/dm-rails/blob/master/lib/dm-rails/storage.rb`. The issue is due to the function exposing sensitive information via the process table. This may allow a local attack to gain access to MySQL credential information.\n","published":"2023-01-26T23:51:40Z","modified":"2023-12-14T22:26:52Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"xaviershay-dm-rails","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-2179"},{"type":"PACKAGE","url":"https://github.com/datamapper/dm-rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/xaviershay-dm-rails/CVE-2015-2179.yml"},{"type":"WEB","url":"http://www.vapid.dhs.org/advisory.php?v=115"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-12-14T22:26:52Z"}}