Safemode Project maintains a focused security-oriented tool addressing authorization and access-control concerns; the durable signal in its vulnerability profile centers on information-disclosure issues and input-validation gaps that affect the core product. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Safemode Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7540CRITICAL rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax. This can lead to deletion of objects for | Jul 21, 2017 | 9.8 | 30 | NO | NO |
CVE-2016-3693HIGH The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obtain sensitive information via t | May 20, 2016 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Safemode Project.
Media articles that mention a CVE ID that affects a product developed by Safemode Project — matched by CVE ID, not by vendor name.