VulnerabilityModified
CVE-2017-7540
rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax.
CRITICAL 9.8EPSS 1.63%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-184
- Affected
- safemode project/safemode
- Source
- secalert@redhat.com
References
- https://github.com/svenfuchs/safemode/pull/23Issue Tracking
- https://github.com/svenfuchs/safemode/pull/23Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.