9.8
CVSSv3

CVE-2017-7540

Published: 21/07/2017 Updated: 09/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

rubygem-safemode, as used in Foreman, versions 1.3.2 and previous versions are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

safemode project safemode

Vendor Advisories

rubygem-safemode, as used in Foreman, versions 132 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation ...