CVE-2014-4998: Lean-Ruport Project Lean-Ruport
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
test/tc_database.rb in the lean-ruport gem 0.3.8 for Ruby places the mysql user password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.
Affected products
- Lean-Ruport Project Lean-Ruport: version 0.3.8 only
Published 2018-01-10. Last modified 2026-06-17.