High severity7.8NVD Advisory· Published Jan 10, 2018· Updated Jun 17, 2026
CVE-2014-5002
CVE-2014-5002
Description
The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lynxRubyGems | < 1.0.0 | 1.0.0 |
Affected products
1Patches
Vulnerability mechanics
References
7- www.openwall.com/lists/oss-security/2014/07/07/23nvdExploitMailing ListThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2014/07/17/5nvdExploitMailing ListThird Party AdvisoryWEB
- www.vapid.dhs.org/advisories/lynx-0.2.0.htmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-94cq-7ccq-cmcmghsaADVISORY
- github.com/panthomakos/lynx/issues/3nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2014-5002ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/lynx/CVE-2014-5002.ymlghsaWEB
News mentions
0No linked articles in our index yet.