VDB
Sign up
HIGH7.8

GHSA-j4gx-p3x5-m987

Echor Ruby Gem credentials can be stolen via process table monitoring

Details

The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to steal the login credentials by watching the process table.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/echor
Introduced in: 0

No fixed version published yet for echor (bundler). Pin to a known-safe version or switch to an alternative.

References