-
CVSS Score
-The commit diff explicitly adds an admin check (:is_admin) as a before filter specifically for create/destroy/update methods. The vulnerability documentation and CWE-284 classification confirm these endpoints lacked proper access control. The patch's targeted nature (only adding checks to these 3 methods) indicates they were the vulnerable entry points.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| chef | rubygems | < 0.9.0 | 0.9.0 |
A Semantic Attack on Google Gemini - Read the Latest Research