CVE-2014-4995
Description
Race condition in lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to obtain sensitive information by reading the MySQL root password from a temporary file before it is removed.
- CVSS Version 3.0
- CVSS Version 2.0
nvd
CVE ID: CVE-2014-4995
Base Score: 7.0
Base Severity: HIGH
Vector String:CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd
CVE ID: CVE-2014-4995
Base Score: 1.9
Base Severity: LOW
Vector String:AV:L/AC:M/Au:N/C:P/I:N/A:N
Refrence: NVD