panthomakos/lynx
Releases3
Frequency2 years 8 months
Last Release
Ruby command line wrapper for MySQL.
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| <= 2.8.9 | 5.3 MEDIUM | 2.6 LOW | ||
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data. | ||||
| < 1.0.0 | — | 2.1 LOW | ||
The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes. | ||||