Affected packages
- simple_form— before 5.0.0
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/plataformatec/simple_form/security/advisories/GHSA-r74q-gxcg-73hx
- https://nvd.nist.gov/vuln/detail/CVE-2019-16676
- https://github.com/heartcombo/simple_form/commit/8c91bd76a5052ddf3e3ab9fd8333f9aa7b2e2dd6
- https://github.com/advisories/GHSA-r74q-gxcg-73hx
- https://github.com/heartcombo/simple_form
- https://github.com/plataformatec/simple_form/commits/master
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/simple_form/CVE-2019-16676.yml
- http://blog.plataformatec.com.br/2019/09/incorrect-access-control-in-simple-form-cve-2019-16676
Structured record: https://osv.dev/vulnerability/GHSA-r74q-gxcg-73hx
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta