CVE-2017-7540

rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:safemode_project:safemode:*:*:*:*:*:ruby:*:*

History

21 Nov 2024, 03:32

Type Values Removed Values Added
References () https://github.com/svenfuchs/safemode/pull/23 - Issue Tracking () https://github.com/svenfuchs/safemode/pull/23 - Issue Tracking

Information

Published : 2017-07-21 22:29

Updated : 2024-11-21 03:32


NVD link : CVE-2017-7540

Mitre link : CVE-2017-7540

CVE.ORG link : CVE-2017-7540


JSON object : View

Products Affected

safemode_project

  • safemode
CWE
CWE-184

Incomplete List of Disallowed Inputs

NVD-CWE-noinfo