Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8474-rc7c-wrhp

Опубликовано: 08 авг. 2018
Источник: github
Github: Прошло ревью

Описание

High severity vulnerability that affects safemode

Withdrawn, accidental duplicate publish.

The safemode rubygem, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.

Пакеты

Наименование

safemode

rubygems
Затронутые версииВерсия исправления

< 1.3.3

1.3.3