Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7540

Опубликовано: 11 июл. 2017
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.3ruby193-rubygem-safemodeWill not fix
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) Installerruby193-rubygem-safemodeWill not fix
Red Hat Satellite 6ruby193-rubygem-safemodeAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-184
https://bugzilla.redhat.com/show_bug.cgi?id=1473243rubygem-safemode: Bypassing the whitelist of safe commands via block_pass

EPSS

Процентиль: 52%
0.00289
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.

CVSS3: 9.8
github
больше 8 лет назад

Safemode Gem Has Incomplete List of Disallowed Inputs

EPSS

Процентиль: 52%
0.00289
Низкий

7.5 High

CVSS3