CVE-2017-7540
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.
Affected (1)
Products: Safemode Project: Safemode
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.3.2 |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Timeline
No history available yet.