CVE-2014-5001: Kcapifony Project Kcapifony
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
lib/ksymfony1.rb in the kcapifony gem 2.1.6 for Ruby places database user passwords on the (1) mysqldump, (2) pg_dump, (3) mysql, and (4) psql command lines, which allows local users to obtain sensitive information by listing the processes.
Affected products
- Kcapifony Project Kcapifony: version 2.1.6 only
Published 2018-01-10. Last modified 2026-06-17.