High severity7.8NVD Advisory· Published Jan 10, 2018· Updated Jun 17, 2026
CVE-2014-5001
CVE-2014-5001
Description
lib/ksymfony1.rb in the kcapifony gem 2.1.6 for Ruby places database user passwords on the (1) mysqldump, (2) pg_dump, (3) mysql, and (4) psql command lines, which allows local users to obtain sensitive information by listing the processes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kcapifonyRubyGems | <= 2.1.6 | — |
Affected products
1Patches
Vulnerability mechanics
References
6- www.vapid.dhs.org/advisories/kcapifony-2.1.6.htmlnvdExploitThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2014/07/07/21nvdMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2014/07/17/5nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-6fcq-3cm2-j3j5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2014-5001ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/kcapifony/CVE-2014-5001.ymlghsaWEB
News mentions
0No linked articles in our index yet.