CVE-2014-4991: Command injection vulnerability
(updated )
It exposes the password to the process table, and is vulnerable to command injection if used in the context of a RoR application. The #{@username} and #{@password} variables aren’t properly sanitized before being passed to the command line.
References
Detect and mitigate CVE-2014-4991 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →