--- gem: codders-dataset cve: 2014-4991 osvdb: 108582 url: https://nvd.nist.gov/vuln/detail/CVE-2014-4991 title: codders-dataset Gem for Ruby lib/dataset/database/mysql.rb and lib/dataset/database/postgresql.rb Process Table Local Plaintext Credential Disclosure date: 2014-06-30 description: (1) lib/dataset/database/mysql.rb and (2) lib/dataset/database/postgresql.rb in the codders-dataset gem 1.3.2.1 for Ruby place credentials on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.