VDB
Sign up
HIGH8.1

GHSA-c92m-rrrc-q5wf

safemode gem allows context-dependent attackers to obtain sensitive information via the inspect method

Quick fix

GHSA-c92m-rrrc-q5wf — safemode: upgrade to the fixed version with the command below.

bundle update safemode

Details

The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obtain sensitive information via the inspect method.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/safemode
Introduced in: 0Fixed in: 1.2.4
Fixbundle update safemode

References