CVE-2018-16476 PUBLISHED

A Broken Access Control vulnerability in Active Job versions >= 4.2.0 allows an attacker to craft user input which can cause Active Job to deserialize it using GlobalId and give them access to information that they should not have. This vulnerability has been fixed in versions 4.2.11, 5.0.7.1, 5.1.6.1, and 5.2.1.1.

EPSS 0.79% · 73.8th percentile

Risk Scores

EPSS Score
0.79%
73.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSrails0, 2:4.1.10-1, 2:4.2.5-1
Cloudflareaccess
Ubuntu:Pro:18.04:LTSrails2:4.2.9-2, 2:4.2.9-4, 2:4.2.10-0ubuntu4
Ubuntu:Pro:22.04:LTSrails2:6.0.3.7+dfsg-2, 2:6.1.4.1+dfsg-8ubuntu2, 2:6.1.4.1+dfsg-8ubuntu2+esm1
Ubuntu:Pro:20.04:LTSrails0, 2:5.2.3+dfsg-3, 2:5.2.3+dfsg-3ubuntu0.1~esm1

Timeline

References

Open in Interactive Console →