Local API Login Credentials Disclosure in paratrooper-pingdom
Low severity
GitHub Reviewed
Published
Oct 24, 2017
to the GitHub Advisory Database
•
Updated Jul 5, 2023
Description
Published by the National Vulnerability Database
Jan 10, 2014
Published to the GitHub Advisory Database
Oct 24, 2017
Reviewed
Jun 16, 2020
Last updated
Jul 5, 2023
The paratrooper-pingdom gem 1.0.0 for Ruby allows local users to obtain the App-Key, username, and password values by listing the curl process.
Vulnerable Code:
From:
paratrooper-pingdom-1.0.0/lib/paratrooper-pingdom.rb
A malicious user could monitor the process tree to steal the API key, username and password for the API login.
References