Sha256: 83fc1e9ea4b7e59049dde03ea862c0a887b969102cb856fa7dfed0035dbc002b

Contents?: true

Size: 565 Bytes

Versions: 3

Compression:

Stored size: 565 Bytes

Contents

---
gem: safemode
cve: 2017-7540
title: Safemode Gem for Ruby is vulnerable to bypassing safe mode limitations
date: 2017-04-05
url: https://nvd.nist.gov/vuln/detail/CVE-2017-7540
description: |
  Safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable 
  to bypassing safe mode limitations via special Ruby syntax. This can
  lead to deletion of objects for which the user does not have delete 
  permissions or possibly to privilege escalation.
patched_versions:
  - ">= 1.3.3"
related:
  url:
    - https://github.com/svenfuchs/safemode/pull/23  

Version data entries

3 entries across 3 versions & 2 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/safemode/CVE-2017-7540.yml
bundler-budit-0.6.2 data/ruby-advisory-db/gems/safemode/CVE-2017-7540.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/safemode/CVE-2017-7540.yml