CVE-2017-7540

rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.
References
Link Resource
https://github.com/svenfuchs/safemode/pull/23 Issue Tracking
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:safemode_project:safemode:*:*:*:*:*:ruby:*:*

Information

Published : 2017-07-21 15:29

Updated : 2019-10-09 16:29


NVD link : CVE-2017-7540

Mitre link : CVE-2017-7540


JSON object : View

Advertisement

dedicated server usa

Products Affected

safemode_project

  • safemode