Vendorslawn-login Projectlawn-loginall versions
Vulnerabilities

lawn-login Project lawn-login

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2014-5000
The login function in lib/lawn.rb in the lawn-login gem 0.0.7 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive information by listing the process.
Published 2018-01-10 · Modified
7.8EPSS 0.005