CVE-2015-3448

EPSS 0.07%

rest-client allows local users to obtain sensitive information by reading the log

Published: 10/24/2017Modified: 4/28/2026
Also known as:GHSA-mx9f-w8qq-q5jfDEBIAN-CVE-2015-3448

Description

REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.

Affected packages (2)

References (6)