5
CVSSv2

CVE-2013-7111

Published: 29/04/2014 Updated: 29/04/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 for Ruby uses the API_KEY on the command line, which allows remote malicious users to obtain sensitive information by listing the processes.

Vulnerable Product Search on Vulmon Subscribe to Product

basespace ruby sdk project basespace ruby sdk 0.1.7