CVE-2015-3448
Low
CVE-2015-3448
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.
Exploit probability
0.4%
Published
April 29, 2015
Required by
Not available
Last source change
April 16, 2026
02 / AFFECTED SOFTWARE
Affected packages
50 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2015-3448
View original source
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.
Open Source Vulnerabilities
GHSA-mx9f-w8qq-q5jf
View original source
REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.
05 / REFERENCES
Further evidence
- http://lists.opensuse.org/opensuse-updates/2015-04/msg00026.html
- http://www.osvdb.org/117461
- http://www.securityfocus.com/bid/74415
- https://github.com/rest-client/rest-client/issues/349
- https://github.com/rest-client/rest-client
- https://nvd.nist.gov/vuln/detail/CVE-2015-3448
- https://web.archive.org/web/20200228154247/http://www.securityfocus.com/bid/74415