CVE-2016-3693

HIGH

Safemode < 1.2.4 - Exposure of Sensitive Information via Inspect Method

Title source: llm
STIX 2.1

Description

The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obtain sensitive information via the inspect method.

References (7)

Core 7
Core References
Various Sources x_refsource_confirm
http://theforeman.org/security.html#2016-3693
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2018:0336
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/04/20/8
Vendor Advisory x_refsource_confirm
http://rubysec.com/advisories/CVE-2016-3693/
Issue Tracking x_refsource_confirm
http://projects.theforeman.org/issues/14635

Scores

CVSS v3 8.1
EPSS 0.0073
EPSS Percentile 72.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200 CWE-264
Status published
Products (2)
rubygems/safemode 0 - 1.2.4RubyGems
safemode_project/safemode < 1.2.3
Published May 20, 2016
Tracked Since Feb 18, 2026