Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5vx5-9q73-wgp4

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Safemode Gem Has Incomplete List of Disallowed Inputs

rubygem-safemode, as used in Foreman, versions 1.3.1 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.

Пакеты

Наименование

safemode

rubygems
Затронутые версииВерсия исправления

< 1.3.2

1.3.2

EPSS

Процентиль: 52%
0.00289
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-184

Связанные уязвимости

CVSS3: 7.5
redhat
больше 8 лет назад

rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.

CVSS3: 9.8
nvd
больше 8 лет назад

rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.

EPSS

Процентиль: 52%
0.00289
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-184