GHSA-q2qw-rmrh-vv42
Dashboard / Vulnerabilities / GHSA-q2qw-rmrh-vv42
Summary: Improper Access Control in activejob
Details: A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-16476, https://github.com/rails/rails/commit/970b0d754be7c71a760d9b807eea32297fd838e3, https://access.redhat.com/errata/RHSA-2019:0600, https://github.com/rails/rails, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activejob/CVE-2018-16476.yml, https://groups.google.com/d/msg/rubyonrails-security/FL4dSdzr2zw/zjKVhF4qBAAJ, https://groups.google.com/forum/#!topic/rubyonrails-security/FL4dSdzr2zw, https://weblog.rubyonrails.org/2018/11/27/Rails-4-2-5-0-5-1-5-2-have-been-released
Affected packages
Package
Name: activejob
Purl: pkg:gem/activejob
Affected ranges
Type: ECOSYSTEM
Events:
