PT-2016-5662 · Ruby · Safemode

Ivan Necas

·

Published

2016-05-20

·

Updated

2023-02-12

·

CVE-2016-3693

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Safemode gem versions prior to 1.2.4
Description The issue allows context-dependent attackers to obtain sensitive information via the inspect method when the Safemode gem is initialized with a delegate object that is a Rails controller.
Recommendations For versions prior to 1.2.4, update to version 1.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the inspect method when the delegate object is a Rails controller until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2016-3693
GHSA-44VC-FPCG-5CC5
GHSA-C92M-RRRC-Q5WF
RHSA-2018:0336

Affected Products

Safemode