Back

LOW

rubygem-rest-client: unsanitized application logging

Published Apr 29, 2015

Description

REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.

Affected products

Remediation

Red Hat mitigation

The permissions on log files can be changed, e.g. using "chmod o-rwx" to prevent anyone but the user and group owner of the file from reading it. Additionally the group permissions can also be removed, e.g. "chmod g-rwx" if only the user owning the file should be able to see it.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 29, 2015
Updated Aug 6, 2024
Reserved Apr 29, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jan 12, 2015
GHSA-MX9F-W8QQ-Q5JF