RubyGems kajam CVE-2014-4999 Information Disclosure Vulnerability
BID:68744
Info
RubyGems kajam CVE-2014-4999 Information Disclosure Vulnerability
| Bugtraq ID: | 68744 |
| Class: | Design Error |
| CVE: |
CVE-2014-4999 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2014 12:00AM |
| Updated: | Jul 07 2014 12:00AM |
| Credit: | Larry W. Cashdollar |
| Vulnerable: |
The ResetTech Dev Team kajam 1.0.3.rc2 |
| Not Vulnerable: | |
Discussion
RubyGems kajam CVE-2014-4999 Information Disclosure Vulnerability
RubyGems kajam is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow an attacker to obtain sensitive information that may aid in further attacks.
RubyGems kajam 1.0.3.rc2 is vulnerable; other versions may also be affected.
RubyGems kajam is prone to an information-disclosure vulnerability.
Successfully exploiting this issue may allow an attacker to obtain sensitive information that may aid in further attacks.
RubyGems kajam 1.0.3.rc2 is vulnerable; other versions may also be affected.
Exploit / POC
RubyGems kajam CVE-2014-4999 Information Disclosure Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
References
RubyGems kajam CVE-2014-4999 Information Disclosure Vulnerability
References:
References:
- kajam Homepage (RubyGems)
- Re: Vulnerability Report for Ruby Gem codders-dataset-1.3.2.1 (etc.) (oss-sec)
- Vulnerability Report for Ruby Gem kajam-1.0.3.rc2 (Larry W. Cashdollar)