High severity7.8NVD Advisory· Published Jan 10, 2018· Updated Jun 17, 2026
CVE-2014-4998
CVE-2014-4998
Description
test/tc_database.rb in the lean-ruport gem 0.3.8 for Ruby places the mysql user password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lean-ruportRubyGems | <= 0.3.8 | — |
Affected products
1Patches
Vulnerability mechanics
References
5- www.vapid.dhs.org/advisories/lean-ruport-0.3.8.htmlnvdExploitThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2014/07/07/18nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2014/07/17/5nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-5g7f-p7jg-v6mvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-4998ghsaADVISORY
News mentions
0No linked articles in our index yet.