Skip to content

Logs password in plaintext

High
rschultheis published GHSA-hhxm-4f85-rgr8 Feb 5, 2019

Package

bundler many_versioned_gem (RubyGems)

Affected versions

< 0.2.1

Patched versions

? I dont know at this time since it hasn't been patched yet

Description

Impact

Logs the password used in plaintext. The password should masked in logs to prevent it leaking.

Patches

Has the problem been patched? What versions should users upgrade to?

Workarounds

none

See also

Are there any links users can visit to find out more information?

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs