rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for which the user does not have delete permissions or possibly to privilege escalation.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2017-07-21T22:00:00Z

Updated: 2024-08-05T16:04:11.899Z

Reserved: 2017-04-05T00:00:00

Link: CVE-2017-7540

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-07-21T22:29:00.330

Modified: 2019-10-09T23:29:43.767

Link: CVE-2017-7540

cve-icon Redhat

Severity : Important

Publid Date: 2017-07-11T00:00:00Z

Links: CVE-2017-7540 - Bugzilla