Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c92m-rrrc-q5wf

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

safemode gem allows context-dependent attackers to obtain sensitive information via the inspect method

The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obtain sensitive information via the inspect method.

Пакеты

Наименование

safemode

rubygems
Затронутые версииВерсия исправления

< 1.2.4

1.2.4

EPSS

Процентиль: 72%
0.00728
Низкий

8.1 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.1
redhat
почти 10 лет назад

The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obtain sensitive information via the inspect method.

CVSS3: 8.1
nvd
больше 9 лет назад

The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obtain sensitive information via the inspect method.

CVSS3: 8.1
debian
больше 9 лет назад

The Safemode gem before 1.2.4 for Ruby, when initialized with a delega ...

EPSS

Процентиль: 72%
0.00728
Низкий

8.1 High

CVSS3

Дефекты

CWE-200