CVE-2014-5002

HIGH

lynx < 1.0.0 - Password Exposure via Command Line

Title source: llm
STIX 2.1

Description

The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.

References (4)

Core 4
Core References
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/07/07/23
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/07/17/5
Third Party Advisory x_refsource_misc
https://github.com/panthomakos/lynx/issues/3
Exploit, Third Party Advisory x_refsource_misc
http://www.vapid.dhs.org/advisories/lynx-0.2.0.html

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 23.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-255
Status published
Products (2)
lynx_project/lynx < 1.0.0
rubygems/lynx 0 - 1.0.0RubyGems
Published Jan 10, 2018
Tracked Since Feb 18, 2026