LOW
GHSA-mx9f-w8qq-q5jf
rest-client allows local users to obtain sensitive information by reading the log
Quick fix
GHSA-mx9f-w8qq-q5jf — rest-client: upgrade to the fixed version with the command below.
bundle update rest-clientDetails
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-3448[ADVISORY]
- https://github.com/rest-client/rest-client/issues/349[WEB]
- https://github.com/rest-client/rest-client[PACKAGE]
- https://web.archive.org/web/20200228154247/http://www.securityfocus.com/bid/74415[WEB]
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00026.html[WEB]