CVE-2014-5000 describes a vulnerability in the lawn-login gem (version 0.0.7) for Ruby, where the login function places user credentials directly on the curl command line. This allows local attackers to easily retrieve sensitive information by listing running processes. The vulnerability is rated as High severity (CVSS 7.8), indicating that an attacker with local access can achieve high confidentiality, integrity, and availability impact with low attack complexity. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.0.7CPE matchmatch criteria | cpe:2.3:a:lawn-login_project:lawn-login:0.0.7:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.