Description
The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 for Ruby uses the API_KEY on the command line, which allows remote attackers to obtain sensitive information by listing the processes.
References (3)
Core 3
Core References
Various Sources x_refsource_misc
http://www.vapid.dhs.org/advisories/bio-basespace-sdk.html
Exploit mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/12/14/2
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/12/15/5
Scores
EPSS
0.0028
EPSS Percentile
51.7%
Details
CWE
CWE-200
Status
published
Products (2)
basespace_ruby_sdk_project/basespace_ruby_sdk
0.1.7
rubygems/bio-basespace-sdk
0RubyGems
Published
Apr 29, 2014
Tracked Since
Feb 18, 2026